cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 39 of 339
CVE-2019-20581P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20581 [CRITICAL] CWE-787 CVE-2019-20581: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. A stack overflow in the HDCP Trustlet causes arbitrary code execution. The Samsung ID is SVE-2019-14665 (August 2019).
nvd
CVE-2020-25053P3CRITICALCVSS 9.8v10.02020-08-31
CVE-2020-25053 [CRITICAL] CVE-2020-25053: An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP a An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).
nvd
CVE-2020-13832P3CRITICALCVSS 9.8v10.02020-06-04
CVE-2020-13832 [CRITICAL] CWE-20 CVE-2020-13832: An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) sof An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine Trustlet allows arbitrary code execution because of memory disclosure, The Samsung IDs are SVE-2020-17117, SVE-2020-17118, SVE-2020-17119, and SVE-2020-17161 (June 2020).
nvd
CVE-2017-18652P3CRITICALCVSS 9.8v6.0v7.0+3 more2020-04-07
CVE-2017-18652 [CRITICAL] CWE-74 CVE-2017-18652: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arb An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017-9299 (September 2017).
nvd
CVE-2023-32889P3HIGHCVSS 7.5v11.0v12.0+1 more2024-01-02
CVE-2023-32889 [HIGH] CWE-787 CVE-2023-32889: In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This co In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161825; Issue ID: MOLY01161825 (MSV-895).
nvd
CVE-2019-20571P3CRITICALCVSS 9.8v8.0v8.12020-03-24
CVE-2019-20571 [CRITICAL] CWE-843 CVE-2019-20571: An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. There is type An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. There is type confusion in the WVDRM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14885 (September 2019).
nvd
CVE-2018-21042P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-04-08
CVE-2018-21042 [CRITICAL] CWE-862 CVE-2018-21042: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Mes An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).
nvd
CVE-2023-33914P3HIGHCVSS 7.5v11.0v12.0+1 more2023-09-04
CVE-2023-33914 [HIGH] CWE-20 CVE-2023-33914: In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input In NIA0 algorithm in Security Mode Command, there is a possible missing verification incorrect input. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2024-29781P3HIGHCVSS 7.5vAndroid kernel2024-06-13
CVE-2024-29781 [HIGH] CWE-125 CVE-2024-29781: In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-52341P3HIGHCVSS 7.5v12.0v13.02024-04-08
CVE-2023-52341 [HIGH] CWE-200 CVE-2023-52341: In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missi In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2017-13319P3HIGHCVSS 7.5v7.0v7.1.1+5 more2024-11-27
CVE-2017-13319 [HIGH] CWE-120 CVE-2017-13319: In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20153P3HIGHCVSS 7.5v14.0v15.02025-01-06
CVE-2024-20153 [HIGH] CWE-304 CVE-2024-20153: In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This c In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
nvd
CVE-2018-14981P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-08-17
CVE-2018-14981 [CRITICAL] CWE-732 CVE-2018-14981: Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI appli Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.
nvd
CVE-2018-14982P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-08-17
CVE-2018-14982 [CRITICAL] CWE-732 CVE-2018-14982: Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS applic Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.
nvd
CVE-2025-61615P3HIGHCVSS 7.5v13.0v14.0+2 more2026-03-09
CVE-2025-61615 [HIGH] CWE-20 CVE-2025-61615: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-61614P3HIGHCVSS 7.5v13.0v14.0+2 more2026-03-09
CVE-2025-61614 [HIGH] CWE-20 CVE-2025-61614: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-61613P3HIGHCVSS 7.5v13.0v14.0+2 more2026-03-09
CVE-2025-61613 [HIGH] CWE-20 CVE-2025-61613: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-61616P3HIGHCVSS 7.5v13.0v14.0+2 more2026-03-09
CVE-2025-61616 [HIGH] CWE-20 CVE-2025-61616: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-61612P3HIGHCVSS 7.5v13.0v14.0+2 more2026-03-09
CVE-2025-61612 [HIGH] CWE-20 CVE-2025-61612: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-71251P3HIGHCVSS 7.5v13.0v14.0+2 more2026-05-06
CVE-2025-71251 [HIGH] CVE-2025-71251: In IMS, there is a possible system crash due to improper input validation. This could lead to remote In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
Google Android vulnerabilities | cvebase