cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 41 of 339
CVE-2018-9496P3HIGHCVSS 7.8v9.02018-10-02
CVE-2018-9496 [HIGH] CWE-787 CVE-2018-9496: In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-9.0 Android ID: A-110769924
nvd
CVE-2015-8073P3CRITICALCVSS 10.0v4.4v5.12015-11-03
CVE-2015-8073 [CRITICAL] CVE-2015-8073: mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 14388161, a different vulnerability than CVE-2015-6608 and CVE-2015-8072.
nvd
CVE-2015-6604P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-6604 [CRITICAL] CWE-119 CVE-2015-6604: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23129786.
nvd
CVE-2015-3869P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3869 [CRITICAL] CWE-119 CVE-2015-3869: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23036083.
nvd
CVE-2015-3870P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3870 [CRITICAL] CWE-119 CVE-2015-3870: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22771132.
nvd
CVE-2015-3823P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3823 [CRITICAL] CWE-119 CVE-2015-3823: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.
nvd
CVE-2024-25988P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-25988 [HIGH] CWE-125 CVE-2024-25988: In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a In SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27220P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27220 [HIGH] CWE-125 CVE-2024-27220: In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds chec In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29749P3HIGHCVSS 8.4vAndroid kernel2024-04-05
CVE-2024-29749 [HIGH] CWE-787 CVE-2024-29749: In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds c In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27226P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27226 [HIGH] CWE-787 CVE-2024-27226: In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27205P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27205 [HIGH] CWE-416 CVE-2024-27205: there is a possible memory corruption due to a use after free. This could lead to local escalation o there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34748P3HIGHCVSS 8.4vAndroid SoC2025-01-28
CVE-2024-34748 [HIGH] CWE-416 CVE-2024-34748: In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to i In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20104P3HIGHCVSS 8.4v12.0v13.0+2 more2024-11-04
CVE-2024-20104 [HIGH] CWE-787 CVE-2024-20104: In da, there is a possible out of bounds write due to a missing bounds check. This could lead to loc In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.
nvd
CVE-2024-40649P3HIGHCVSS 8.4vAndroid SoC2025-01-28
CVE-2024-40649 [HIGH] CWE-416 CVE-2024-40649: In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40651P3HIGHCVSS 8.4vAndroid SoC2025-01-28
CVE-2024-40651 [HIGH] CWE-416 CVE-2024-40651: In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40672P3HIGHCVSS 8.4v12.0v12.1+6 more2025-01-28
CVE-2024-40672 [HIGH] CWE-281 CVE-2024-40672: In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40677P3HIGHCVSS 8.4v12.0v12.1+8 more2025-01-28
CVE-2024-40677 [HIGH] CWE-862 CVE-2024-40677: In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass facto In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40669P3HIGHCVSS 8.4vAndroid SoC2025-01-28
CVE-2024-40669 [HIGH] CWE-416 CVE-2024-40669: In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40670P3HIGHCVSS 8.4vAndroid SoC2025-01-28
CVE-2024-40670 [HIGH] CWE-416 CVE-2024-40670: In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9497P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-10-02
CVE-2018-9497 [HIGH] CWE-787 CVE-2018-9497: In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bou In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 And
nvd
Google Android vulnerabilities | cvebase