cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 42 of 339
CVE-2020-0458P3HIGHCVSS 7.8v8.0v8.1+3 more2020-12-14
CVE-2020-0458 [HIGH] CWE-190 CVE-2020-0458: In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-8.0 Android-8.1Andro
nvd
CVE-2015-6601P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-6601 [CRITICAL] CWE-119 CVE-2015-6601: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22935234.
nvd
CVE-2015-3871P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3871 [CRITICAL] CWE-119 CVE-2015-3871: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23031033.
nvd
CVE-2015-6598P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-6598 [CRITICAL] CWE-20 CVE-2015-6598: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23306638.
nvd
CVE-2015-3867P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3867 [CRITICAL] CWE-119 CVE-2015-3867: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23213430.
nvd
CVE-2015-6599P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-6599 [CRITICAL] CWE-119 CVE-2015-6599: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23416608.
nvd
CVE-2015-6603P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-6603 [CRITICAL] CWE-119 CVE-2015-6603: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23227354.
nvd
CVE-2015-3872P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3872 [CRITICAL] CWE-119 CVE-2015-3872: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23346388.
nvd
CVE-2015-6600P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-6600 [CRITICAL] CWE-119 CVE-2015-6600: libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or c libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22882938.
nvd
CVE-2015-3877P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3877 [CRITICAL] CWE-119 CVE-2015-3877: Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or c Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696.
nvd
CVE-2020-0034P3HIGHCVSS 7.5v8.0v8.1+1 more2020-03-10
CVE-2020-0034 [HIGH] CWE-125 CVE-2020-0034: In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input v In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-
nvd
CVE-2021-0435P3HIGHCVSS 7.5v8.1v9.0+3 more2021-04-13
CVE-2021-0435 [HIGH] CWE-665 CVE-2021-0435: In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitializ In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174150451
nvd
CVE-2021-0313P3HIGHCVSS 7.5v8.0v8.1+8 more2021-01-11
CVE-2021-0313 [HIGH] CWE-20 CVE-2021-0313: In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to i In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1;
nvd
CVE-2020-0413P3HIGHCVSS 7.5v8.0v8.1+4 more2020-10-14
CVE-2020-0413 [HIGH] CWE-125 CVE-2020-0413: In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a miss In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-1
nvd
CVE-2020-0381P3HIGHCVSS 7.5v8.0v8.1+4 more2020-09-17
CVE-2020-0381 [HIGH] CWE-190 CVE-2020-0381: In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. Thi In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure in a highly constrained process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11
nvd
CVE-2020-0463P3HIGHCVSS 7.5v8.0v8.1+4 more2020-12-14
CVE-2020-0463 [HIGH] CWE-125 CVE-2020-0463: In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a mi In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Andr
nvd
CVE-2021-0522P3HIGHCVSS 7.5v9.0v10.0+2 more2021-06-21
CVE-2021-0522 [HIGH] CWE-125 CVE-2021-0522: In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-174182139
nvd
CVE-2019-1992P3HIGHCVSS 7.5v7.0v7.1.1+4 more2019-02-28
CVE-2019-1992 [HIGH] CWE-362 CVE-2019-1992: In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race cond In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID:
nvd
CVE-2020-0391P3HIGHCVSS 7.8v9.0v10.0+1 more2020-09-17
CVE-2020-0391 [HIGH] CVE-2020-0391: In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as Syste In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-158
nvd
CVE-2018-9341P3HIGHCVSS 7.8v6.0v6.0.1+10 more2024-11-19
CVE-2018-9341 [HIGH] CWE-787 CVE-2018-9341: In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing boun In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
Google Android vulnerabilities | cvebase