cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 50 of 339
CVE-2023-35661P3HIGHCVSS 7.5vAndroid kernel2023-10-11
CVE-2023-35661 [HIGH] CWE-125 CVE-2023-35661: In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-6616P3CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6616 [CRITICAL] CWE-119 CVE-2015-6616: mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to exec mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 24630158 and 23882800, a different vulnerability than CVE-2015-8505, CVE-2015-8506, and CVE-2015-8507.
nvd
CVE-2024-32894P3HIGHCVSS 7.5vAndroid kernel2024-06-13
CVE-2024-32894 [HIGH] CWE-125 CVE-2024-32894: In bc_get_converted_received_bearer of bc_utilities.c, there is a possible out of bounds read due to In bc_get_converted_received_bearer of bc_utilities.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-33915P3HIGHCVSS 7.5v11.02023-09-04
CVE-2023-33915 [HIGH] CWE-862 CVE-2023-33915: In LTE protocol stack, there is a possible missing permission check. This could lead to remote infor In LTE protocol stack, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2024-27206P3HIGHCVSS 7.5v13.0v132024-03-11
CVE-2024-27206 [HIGH] CWE-125 CVE-2024-27206: there is a possible out of bounds read due to a missing bounds check. This could lead to remote info there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-22011P3HIGHCVSS 7.5v132024-03-11
CVE-2024-22011 [HIGH] CWE-125 CVE-2024-22011: In ss_ProcessRejectComponent of ss_MmConManagement.c, there is a possible out of bounds read due to In ss_ProcessRejectComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-5524P3CRITICALCVSS 9.8v4.42020-04-10
CVE-2015-5524 [CRITICAL] CWE-120 CVE-2015-5524: An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-05-13 An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-05-13. There is a buffer overflow in datablock_write because the amount of received data is not validated. The Samsung ID is SVE-2015-4018 (December 2015).
nvd
CVE-2026-0109P3HIGHCVSS 7.5vAndroid kernel2026-03-10
CVE-2026-0109 [HIGH] CWE-754 CVE-2026-0109: In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition che In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49734P3HIGHCVSS 7.5v14.0v15.0+2 more2025-01-21
CVE-2024-49734 [HIGH] CWE-200 CVE-2024-49734: In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determi In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9484P3HIGHCVSS 7.5v7.0v7.1.1+9 more2024-11-20
CVE-2018-9484 [HIGH] CWE-125 CVE-2018-9484: In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missin In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9419P3HIGHCVSS 7.5v7.0v7.1.1+7 more2024-11-19
CVE-2018-9419 [HIGH] CWE-125 CVE-2018-9419: In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bou In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20007P3HIGHCVSS 7.5v12.0v13.0+1 more2024-02-05
CVE-2024-20007 [HIGH] CWE-362 CVE-2024-20007: In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441369; Issue ID: ALPS08441369.
nvd
CVE-2025-61617P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-61617 [HIGH] CVE-2025-61617: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-61607P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-61607 [HIGH] CVE-2025-61607: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-11132P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-11132 [HIGH] CVE-2025-11132: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-61610P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-61610 [HIGH] CVE-2025-61610: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-11131P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-11131 [HIGH] CVE-2025-11131: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-61609P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-61609 [HIGH] CVE-2025-61609: In modem, there is a possible system crash due to improper input validation. This could lead to remo In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-61608P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-61608 [HIGH] CVE-2025-61608: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-61618P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-61618 [HIGH] CVE-2025-61618: In nr modem, there is a possible system crash due to improper input validation. This could lead to r In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
Google Android vulnerabilities | cvebase