cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 323 of 339
CVE-2026-20437P4MEDIUMCVSS 4.4v15.02026-03-02
CVE-2026-20437 [MEDIUM] CWE-416 CVE-2026-20437: In MAE, there is a possible system crash due to use after free. This could lead to local denial of s In MAE, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431940; Issue ID: MSV-5843.
nvd
CVE-2017-3544P4LOWCVSS 3.7v4.4.4v5.0.2+6 more2017-04-24
CVE-2017-3544 [LOW] CVE-2017-3544: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: N Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedde
nvd
CVE-2021-25429P4MEDIUMCVSS 4.3v8.1v9.0+2 more2021-07-08
CVE-2021-25429 [MEDIUM] CWE-269 CVE-2021-25429: Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
nvd
CVE-2019-2191P4MEDIUMCVSS 4.3v10.0vAndroid kernel2019-09-27
CVE-2019-2191 [MEDIUM] CWE-119 CVE-2019-2191: In LG's LAF component, there is a possible leak of information in a protected disk partition due to In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-68770980
nvd
CVE-2019-2190P4MEDIUMCVSS 4.3v10.0vAndroid kernel2019-09-27
CVE-2019-2190 [MEDIUM] CWE-119 CVE-2019-2190: In LG's LAF component, there is a possible leak of information in a protected disk partition due to In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-68771598
nvd
CVE-2022-20541P4MEDIUMCVSS 4.2v13.0vAndroid-132022-12-16
CVE-2022-20541 [MEDIUM] CWE-125 CVE-2022-20541: In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing boun In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238083126
nvd
CVE-2023-20839P4MEDIUMCVSS 4.2v11.0v12.02023-09-04
CVE-2023-20839 [MEDIUM] CWE-125 CVE-2023-20839: In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409.
nvd
CVE-2023-20846P4MEDIUMCVSS 4.2v11.0v12.02023-09-04
CVE-2023-20846 [MEDIUM] CWE-125 CVE-2023-20846: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; Issue ID: ALPS07340098.
nvd
CVE-2023-20844P4MEDIUMCVSS 4.2v11.0v12.02023-09-04
CVE-2023-20844 [MEDIUM] CWE-125 CVE-2023-20844: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Issue ID: ALPS07340121.
nvd
CVE-2023-20845P4MEDIUMCVSS 4.2v11.0v12.02023-09-04
CVE-2023-20845 [MEDIUM] CWE-125 CVE-2023-20845: In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357.
nvd
CVE-2023-20843P4MEDIUMCVSS 4.2v11.0v12.02023-09-04
CVE-2023-20843 [MEDIUM] CWE-125 CVE-2023-20843: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; Issue ID: ALPS07340119.
nvd
CVE-2020-0199P4MEDIUMCVSS 4.1v10.0vAndroid-102020-06-11
CVE-2020-0199 [MEDIUM] CWE-362 CVE-2020-0199: In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due t In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142142406
nvd
CVE-2023-20717P4MEDIUMCVSS 4.1v11.0v12.0+1 more2023-05-15
CVE-2023-20717 [MEDIUM] CVE-2023-20717: In vcu, there is a possible leak of dma buffer due to a race condition. This could lead to local inf In vcu, there is a possible leak of dma buffer due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645185; Issue ID: ALPS07645185.
nvd
CVE-2023-21178P4MEDIUMCVSS 4.1v13.0vAndroid-132023-06-28
CVE-2023-21178 [MEDIUM] CWE-362 CVE-2023-21178: In installKey of KeyUtil.cpp, there is a possible failure of file encryption due to a race condition In installKey of KeyUtil.cpp, there is a possible failure of file encryption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-140762419
nvd
CVE-2024-32923P4MEDIUMCVSS 4.0vAndroid kernel2024-06-13
CVE-2024-32923 [MEDIUM] CVE-2024-32923: there is a possible cellular denial of service due to a logic error in the code. This could lead to there is a possible cellular denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26424P4MEDIUMCVSS 4.0v15.0v152025-09-04
CVE-2025-26424 [MEDIUM] CWE-284 CVE-2025-26424: In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic er In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20065P4MEDIUMCVSS 4.0v12.0v13.0+1 more2024-06-03
CVE-2024-20065 [MEDIUM] CWE-284 CVE-2024-20065: In telephony, there is a possible information disclosure due to a missing permission check. This cou In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.
nvd
CVE-2022-20330P4LOWCVSS 3.5v13.0vAndroid-132022-08-12
CVE-2022-20330 [LOW] CWE-862 CVE-2022-20330: In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awaren In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-181962588
nvd
CVE-2022-28784P4LOWCVSS 3.3v10.0v11.0+1 more2022-05-03
CVE-2022-28784 [LOW] CWE-22 CVE-2022-28784: Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to li Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.
nvd
CVE-2015-1525P4MEDIUMCVSS 5.5fixed in 5.12020-01-24
CVE-2015-1525 [MEDIUM] CWE-20 CVE-2015-1525: audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.
nvd
Google Android vulnerabilities | cvebase