Google Android vulnerabilities
9,713 known vulnerabilities affecting google/android.
Total CVEs
9,713
CISA KEV
49
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5220MEDIUM3343LOW265UNKNOWN2
Vulnerabilities
Page 35 of 486
CVE-2015-9064HIGHCVSS 9.82018-04-01
CVE-2015-9064 [CRITICAL] CVE-2015-9064: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2015-9064
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-37546801*
android
CVE-2018-5855HIGHCVSS 9.82019-04-01
CVE-2018-5855 [CRITICAL] CVE-2018-5855: WLAN HOST
Android Security Bulletin 2019-04-01
CVE: CVE-2018-5855
Severity: HIGH
Type: N/A
Component: WLAN HOST
References: A-77527719
QC-CR#2193421
android
CVE-2017-14910HIGHCVSS 9.82018-02-01
CVE-2017-14910 [CRITICAL] CVE-2017-14910: Closed-source component
Android Security Bulletin 2018-02-01
CVE: CVE-2017-14910
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-62212114*
android
CVE-2021-1933CRITICALCVSS 9.82021-09-01
CVE-2021-1933 [CRITICAL] CVE-2021-1933: Closed-source component
Android Security Bulletin 2021-09-01
CVE: CVE-2021-1933
Severity: CRITICAL
Component: Closed-source component
References: A-181682124
*
android
CVE-2019-10533CRITICALCVSS 9.82019-09-01
CVE-2019-10533 [CRITICAL] CVE-2019-10533: Closed-source component
Android Security Bulletin 2019-09-01
CVE: CVE-2019-10533
Severity: CRITICAL
Type: N/A
Component: Closed-source component
References: A-134437210*
android
CVE-2019-2258CRITICALCVSS 9.82019-09-01
CVE-2019-2258 [CRITICAL] CVE-2019-2258: Closed-source component
Android Security Bulletin 2019-09-01
CVE: CVE-2019-2258
Severity: CRITICAL
Type: N/A
Component: Closed-source component
References: A-123998354*
android
CVE-2019-2324HIGHCVSS 9.82019-09-01
CVE-2019-2324 [CRITICAL] CVE-2019-2324: Audio
Android Security Bulletin 2019-09-01
CVE: CVE-2019-2324
Severity: HIGH
Type: N/A
Component: Audio
References: A-132173296
QC-CR#2372292
android
CVE-2016-6695CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-6695 [CRITICAL] CWE-119 CVE-2016-6695: sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted visualizer data length, aka Qualcomm internal bug CR 1033540.
nvdandroid
CVE-2018-3594HIGHCVSS 9.82018-04-01
CVE-2018-3594 [CRITICAL] CVE-2018-3594: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2018-3594
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-71501112*
android
CVE-2016-10501HIGHCVSS 9.82018-04-01
CVE-2016-10501 [CRITICAL] CVE-2016-10501: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2016-10501
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-62261303*
android
CVE-2014-9972HIGHCVSS 9.82018-04-01
CVE-2014-9972 [CRITICAL] CVE-2014-9972: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2014-9972
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-37546853*
android
CVE-2020-25279CRITICALCVSS 9.8v8.0v8.1+2 more2020-09-11
CVE-2020-25279 [CRITICAL] CWE-120 CVE-2020-25279: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets)
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-2020-18098 (September 2020).
nvd
CVE-2019-2317CRITICALCVSS 9.82020-03-01
CVE-2019-2317 [CRITICAL] CVE-2019-2317: Closed-source component
Android Security Bulletin 2020-03-01
CVE: CVE-2019-2317
Severity: CRITICAL
Type: N/A
Component: Closed-source component
References: A-134436812*
android
CVE-2018-3590HIGHCVSS 9.82018-04-01
CVE-2018-3590 [CRITICAL] CVE-2018-3590: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2018-3590
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-71501106*
android
CVE-2017-18136HIGHCVSS 9.82018-04-01
CVE-2017-18136 [CRITICAL] CVE-2017-18136: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2017-18136
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-68989810*
android
CVE-2017-11011HIGHCVSS 9.82018-04-01
CVE-2017-11011 [CRITICAL] CVE-2017-11011: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2017-11011
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-68326823*
android
CVE-2017-18140HIGHCVSS 9.82018-04-01
CVE-2017-18140 [CRITICAL] CVE-2017-18140: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2017-18140
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-68989811*
android
CVE-2014-10046HIGHCVSS 9.82018-04-01
CVE-2014-10046 [CRITICAL] CVE-2014-10046: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2014-10046
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-62261408*
android
CVE-2017-18144HIGHCVSS 9.82018-04-01
CVE-2017-18144 [CRITICAL] CVE-2017-18144: Closed-source component
Android Security Bulletin 2018-04-01
CVE: CVE-2017-18144
Severity: HIGH
Type: N/A
Component: Closed-source component
References: A-70221450*
android
CVE-2015-6602CRITICALCVSS 9.3≤ 5.1.12015-10-02
CVE-2015-6602 [CRITICAL] CWE-20 CVE-2015-6602: libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via craft
libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.
nvdandroid