Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 38 of 483
CVE-2018-9405MEDIUMCVSS 6.7vAndroid Kernel2025-01-18
CVE-2018-9405 [MEDIUM] CWE-787 CVE-2018-9405: In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing b In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-13322CRITICALCVSS 10.0v6.0v6.0.1+6 more2025-01-17
CVE-2017-13322 [CRITICAL] CWE-783 CVE-2017-13322: In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9375HIGHCVSS 7.8v6.0v6.0.1+6 more2025-01-17
CVE-2018-9375 [HIGH] CWE-269 CVE-2018-9375: In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete word In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9382HIGHCVSS 7.8v6.0v6.0.1+4 more2025-01-17
CVE-2018-9382 [HIGH] CWE-862 CVE-2018-9382: In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot fro In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9434HIGHCVSS 7.8v6.0v6.0.1+6 more2025-01-17
CVE-2018-9434 [HIGH] CWE-276 CVE-2018-9434: In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomiz In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9383MEDIUMCVSS 4.4vAndroid kernel2025-01-17
CVE-2018-9383 [MEDIUM] CWE-125 CVE-2018-9383: In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bound In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9379MEDIUMCVSS 5.5v6.0v6.0.1+6 more2025-01-17
CVE-2018-9379 [MEDIUM] CWE-200 CVE-2018-9379: In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of delet In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9447MEDIUMCVSS 5.5v6.0v6.0.1+3 more2025-01-17
CVE-2018-9447 [MEDIUM] CWE-400 CVE-2018-9447: In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9384MEDIUMCVSS 4.4vAndroid Kernel2025-01-17
CVE-2018-9384 [MEDIUM] CWE-200 CVE-2018-9384: In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This co In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35685HIGHCVSS 7.8vAndroid SoC2025-01-08
CVE-2023-35685 [HIGH] CWE-416 CVE-2023-35685: In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic err In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20148CRITICALCVSS 9.8v13.0v14.0+1 more2025-01-06
CVE-2024-20148 [CRITICAL] CWE-787 CVE-2024-20148: In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.
nvdandroid
CVE-2024-20146HIGHCVSS 8.1v13.0v14.0+1 more2025-01-06
CVE-2024-20146 [HIGH] CWE-787 CVE-2024-20146: In wlan STA driver, there is a possible out of bounds write due to improper input validation. This c In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.
nvdandroid
CVE-2024-20153HIGHCVSS 7.5v14.0v15.02025-01-06
CVE-2024-20153 [HIGH] CWE-304 CVE-2024-20153: In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This c In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
nvd
CVE-2024-20144MEDIUMCVSS 6.6v13.0v14.0+1 more2025-01-06
CVE-2024-20144 [MEDIUM] CWE-787 CVE-2024-20144: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2041.
nvdandroid
CVE-2024-20145MEDIUMCVSS 6.6v14.0v15.02025-01-06
CVE-2024-20145 [MEDIUM] CWE-787 CVE-2024-20145: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040.
nvdandroid
CVE-2024-20143MEDIUMCVSS 6.6v12.0v13.0+2 more2025-01-06
CVE-2024-20143 [MEDIUM] CWE-787 CVE-2024-20143: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2069.
nvdandroid
CVE-2024-20105MEDIUMCVSS 6.7v12.0v13.0+2 more2025-01-06
CVE-2024-20105 [MEDIUM] CWE-787 CVE-2024-20105: In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09062027; Issue ID: MSV-1743.
nvdandroid
CVE-2024-20140MEDIUMCVSS 6.7v12.0v13.0+2 more2025-01-06
CVE-2024-20140 [MEDIUM] CWE-787 CVE-2024-20140: In power, there is a possible out of bounds write due to a missing bounds check. This could lead to In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09270402; Issue ID: MSV-2020.
nvdandroid
CVE-2024-20152MEDIUMCVSS 4.4v13.0v14.0+1 more2025-01-06
CVE-2024-20152 [MEDIUM] CWE-617 CVE-2024-20152: In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.
nvd
CVE-2024-53842CRITICALCVSS 9.8vAndroid kernel2025-01-03
CVE-2024-53842 [CRITICAL] CWE-787 CVE-2024-53842: In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd