cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 44 of 339
CVE-2018-9338P3HIGHCVSS 7.8v6.0v6.0.1+10 more2024-11-19
CVE-2018-9338 [HIGH] CWE-787 CVE-2018-9338: In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missi In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0036P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-16
CVE-2024-0036 [HIGH] CWE-284 CVE-2024-0036: In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass t In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43085P3HIGHCVSS 7.8v12.0v12.1+8 more2024-11-13
CVE-2024-43085 [HIGH] CWE-276 CVE-2024-43085: In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34729P3HIGHCVSS 7.8vAndroid SoC2024-11-13
CVE-2024-34729 [HIGH] CVE-2024-34729: In multiple locations, there is a possible arbitrary code execution due to a logic error in the code In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9389P3HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9389 [HIGH] CWE-787 CVE-2018-9389: In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40658P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40658 [HIGH] CWE-787 CVE-2024-40658: In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a h In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23698P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-23698 [HIGH] CWE-787 CVE-2024-23698: In RGXFWChangeOSidPriority of rgxfwutils.c, there is a possible arbitrary code execution due to a mi In RGXFWChangeOSidPriority of rgxfwutils.c, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31318P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31318 [HIGH] CWE-862 CVE-2024-31318: In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without us In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29741P3HIGHCVSS 7.8vAndroid kernel2024-04-05
CVE-2024-29741 [HIGH] CWE-269 CVE-2024-29741: In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43081P3HIGHCVSS 7.8v12.0v12.1+8 more2024-11-13
CVE-2024-43081 [HIGH] CWE-276 CVE-2024-43081: In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restrictio In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27212P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27212 [HIGH] CWE-787 CVE-2024-27212: In init_data of , there is a possible out of bounds write due to a missing bounds check. This could In init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23715P3HIGHCVSS 7.8vAndroid SoC2024-11-13
CVE-2024-23715 [HIGH] CWE-787 CVE-2024-23715: In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31313P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31313 [HIGH] CWE-787 CVE-2024-31313: In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an in In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40128P3HIGHCVSS 7.8v11.0v12.0+6 more2023-10-27
CVE-2023-40128 [HIGH] CWE-787 CVE-2023-40128: In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer ov In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0089P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-0089 [HIGH] CWE-693 CVE-2025-0089: In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in th In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40662P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40662 [HIGH] CWE-269 CVE-2024-40662: In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0079P3HIGHCVSS 7.8v12.0v12.1+8 more2025-08-26
CVE-2025-0079 [HIGH] CWE-250 CVE-2025-0079: In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted du In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31311P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31311 [HIGH] CWE-787 CVE-2024-31311: In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a mis In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26464P3HIGHCVSS 7.8v15.0v152025-09-04
CVE-2025-26464 [HIGH] CWE-693 CVE-2025-26464: In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launc In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32331P3HIGHCVSS 7.8v15.0v16.0+2 more2025-09-04
CVE-2025-32331 [HIGH] CWE-693 CVE-2025-32331: In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning du In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase