Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 40 of 339
CVE-2025-22423P3HIGHCVSS 7.5v13.0v14.0+4 more2025-09-02
CVE-2025-22423 [HIGH] CWE-125 CVE-2025-22423: In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bou
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-53834P3HIGHCVSS 7.5vAndroid kernel2025-01-03
CVE-2024-53834 [HIGH] CWE-125 CVE-2024-53834: In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due
In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20138P3HIGHCVSS 7.5v13.0v14.0+1 more2024-12-02
CVE-2024-20138 [HIGH] CWE-125 CVE-2024-20138: In wlan driver, there is a possible out of bound read due to improper input validation. This could l
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.
nvd
CVE-2015-3835P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3835 [CRITICAL] CWE-119 CVE-2015-3835: Buffer overflow in the OMXNodeInstance::emptyBuffer function in omx/OMXNodeInstance.cpp in libstagef
Buffer overflow in the OMXNodeInstance::emptyBuffer function in omx/OMXNodeInstance.cpp in libstagefright in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug 20634516.
nvd
CVE-2018-21038P3CRITICALCVSS 9.8v7.0v7.1.0+2 more2020-04-08
CVE-2018-21038 [CRITICAL] CWE-287 CVE-2018-21038: An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's star
An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018).
nvd
CVE-2025-36894P3HIGHCVSS 7.5vAndroid kernel2025-09-04
CVE-2025-36894 [HIGH] CWE-476 CVE-2025-36894: In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial
In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-20576P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2019-20576 [CRITICAL] CWE-89 CVE-2019-20576: An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Prov
An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019).
nvd
CVE-2023-33913P3HIGHCVSS 7.2v11.0v12.02023-08-07
CVE-2023-33913 [HIGH] CWE-787 CVE-2023-33913: In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer
In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalation of privilege with System execution privileges needed
nvd
CVE-2024-20034P3HIGHCVSS 7.2v12.0v13.0+1 more2024-03-04
CVE-2024-20034 [HIGH] CWE-20 CVE-2024-20034: In battery, there is a possible escalation of privilege due to a missing bounds check. This could le
In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08488849; Issue ID: ALPS08488849.
nvd
CVE-2019-2018P3HIGHCVSS 8.8v8.1v9.0+1 more2019-06-19
CVE-2019-2018 [HIGH] CWE-287 CVE-2019-2018: In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password
In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. Remote user interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-110172241
nvd
CVE-2019-2016P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-2016 [HIGH] CWE-20 CVE-2019-2016: In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input v
In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Andro
nvd
CVE-2016-0842P3HIGHCVSS 8.4v6.0v6.0.12016-04-18
CVE-2016-0842 [HIGH] CWE-119 CVE-2016-0842: The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Co
The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25818142.
nvd
CVE-2016-0840P3HIGHCVSS 8.4v6.0v6.0.12016-04-18
CVE-2016-0840 [HIGH] CWE-119 CVE-2016-0840: Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x
Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26399350.
nvd
CVE-2016-0850P3HIGHCVSS 8.8v4.0v4.0.1+20 more2016-04-18
CVE-2016-0850 [HIGH] CWE-264 CVE-2016-0850: The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.
The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to bypass intended pairing restrictions via a crafted device, aka internal bug 26551752.
nvd
CVE-2021-25356P3HIGHCVSS 8.8v8.1v9.0+2 more2021-04-09
CVE-2021-25356 [HIGH] CWE-20 CVE-2021-25356: An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allow
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.
nvd
CVE-2022-20429P3HIGHCVSS 8.8v10.0v11.0+3 more2022-10-11
CVE-2022-20429 [HIGH] CVE-2022-20429: In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This
In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220741473
nvd
CVE-2016-0836P3HIGHCVSS 7.8v6.0v6.0.12016-04-18
CVE-2016-0836 [HIGH] CWE-119 CVE-2016-0836: Stack-based buffer overflow in decoder/impeg2d_vld.c in mediaserver in Android 6.x before 2016-04-01
Stack-based buffer overflow in decoder/impeg2d_vld.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25812590.
nvd
CVE-2015-3868P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3868 [CRITICAL] CWE-119 CVE-2015-3868: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23270724.
nvd
CVE-2021-0594P3HIGHCVSS 8.0v8.1v9.0+3 more2021-07-14
CVE-2021-0594 [HIGH] CWE-74 CVE-2021-0594: In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to impr
In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote (proximal, NFC) escalation of privilege allowing an attacker to deceive a user into allowing a Bluetooth connection with no additional execution privileges needed. User interaction is needed for exploitation
nvd
CVE-2018-9503P3HIGHCVSS 7.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9503 [HIGH] CWE-125 CVE-2018-9503: In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missi
In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 A
nvd