cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 5 of 339
CVE-2022-20472P2CRITICALCVSS 9.8v10.0v11.0+4 more2022-12-13
CVE-2022-20472 [CRITICAL] CWE-125 CVE-2022-20472: In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-2392
nvd
CVE-2024-27228P2CRITICALCVSS 9.8v13.0v132024-03-11
CVE-2024-27228 [CRITICAL] CWE-787 CVE-2024-27228: there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote cod there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-2023P3HIGHCVSS 7.8PoCv8.0v8.1+2 more2019-06-19
CVE-2019-2023 [HIGH] CWE-732 CVE-2019-2023: In ServiceManager::add function in the hardware service manager, there is an insecure permissions ch In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could allow an app to add or replace a HAL service with its own service, gaining code execution in a privileged process.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-121035042Upstream ker
nvd
CVE-2022-20145P2CRITICALCVSS 9.8v11.0vAndroid-112022-06-15
CVE-2022-20145 [CRITICAL] CVE-2022-20145: In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-
nvd
CVE-2025-0075P2CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-0075 [CRITICAL] CWE-416 CVE-2025-0075: In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary co In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0074P2CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-0074 [CRITICAL] CWE-416 CVE-2025-0074: In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code d In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22403P2CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-22403 [CRITICAL] CWE-416 CVE-2025-22403: In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22408P2CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-22408 [CRITICAL] CWE-416 CVE-2025-22408: In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a us In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-0785P3MEDIUMCVSS 6.5PoCv4.0v4.0.1+28 more2017-09-14
CVE-2017-0785 [MEDIUM] CWE-200 CVE-2017-0785: A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
nvd
CVE-2024-43091P2CRITICALCVSS 9.8v12.0v12.1+8 more2024-11-13
CVE-2024-43091 [CRITICAL] CWE-190 CVE-2024-43091: In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer o In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49748P2CRITICALCVSS 9.8v12.0v12.1+8 more2025-01-21
CVE-2024-49748 [CRITICAL] CWE-787 CVE-2024-49748: In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9430P2CRITICALCVSS 9.8v6.0v6.0.1+8 more2024-12-02
CVE-2018-9430 [CRITICAL] CWE-787 CVE-2018-9430: In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds c In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-53842P2CRITICALCVSS 9.8vAndroid kernel2025-01-03
CVE-2024-53842 [CRITICAL] CWE-787 CVE-2024-53842: In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20100P2CRITICALCVSS 9.8v12.0v13.0+1 more2024-10-07
CVE-2024-20100 [CRITICAL] CWE-787 CVE-2024-20100: In wlan driver, there is a possible out of bounds write due to improper input validation. This could In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.
nvd
CVE-2024-32905P2CRITICALCVSS 9.8vAndroid kernel2024-06-13
CVE-2024-32905 [CRITICAL] CWE-787 CVE-2024-32905: In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incor In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20101P2CRITICALCVSS 9.8v13.0v14.0+1 more2024-10-07
CVE-2024-20101 [CRITICAL] CWE-787 CVE-2024-20101: In wlan driver, there is a possible out of bounds write due to improper input validation. This could In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.
nvd
CVE-2021-39675P2CRITICALCVSS 9.8v12.0vAndroid-122022-02-11
CVE-2021-39675 [CRITICAL] CWE-787 CVE-2021-39675: In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflo In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-205729183
nvd
CVE-2016-2494P3HIGHCVSS 7.8PoCv4.0v4.0.1+20 more2016-06-13
CVE-2016-2494 [HIGH] CWE-264 CVE-2016-2494: Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5. Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28085658.
nvd
CVE-2024-0031P2CRITICALCVSS 9.8v11.0v12.0+8 more2024-02-16
CVE-2024-0031 [CRITICAL] CWE-787 CVE-2024-0031: In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write du In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21250P2CRITICALCVSS 9.8v11.0v12.0+6 more2023-07-13
CVE-2023-21250 [CRITICAL] CWE-787 CVE-2023-21250: In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bou In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase