Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 52 of 339
CVE-2017-0788P3HIGHCVSS 8.8v7.1.22017-09-08
CVE-2017-0788 [HIGH] CVE-2017-0788: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722328. References: B-V2017053103.
nvd
CVE-2021-25361P3HIGHCVSS 8.8v10.0v11.02021-04-09
CVE-2021-25361 [HIGH] CWE-22 CVE-2021-25361: An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows loc
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.
nvd
CVE-2017-0540P3HIGHCVSS 7.8v5.0v5.0.1+9 more2017-04-07
CVE-2017-0540 [HIGH] CWE-119 CVE-2017-0540: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2017-0663P3HIGHCVSS 7.8v4.4.4v5.0.2+6 more2017-06-14
CVE-2017-0663 [HIGH] CWE-787 CVE-2017-0663: A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted
A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1,
nvd
CVE-2017-0474P3HIGHCVSS 7.8v7.0v7.1.0+1 more2017-03-08
CVE-2017-0474 [HIGH] CWE-119 CVE-2017-0474: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 7.0, 7.1.1. Android ID: A
nvd
CVE-2020-0181P3HIGHCVSS 7.5v10.0vAndroid-102020-06-11
CVE-2020-0181 [HIGH] CWE-190 CVE-2020-0181: In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an int
In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145075076
nvd
CVE-2018-9427P3HIGHCVSS 7.8v8.0v8.12018-11-06
CVE-2018-9427 [HIGH] CWE-787 CVE-2018-9427: In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect boun
In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-77486542.
nvd
CVE-2017-0478P3HIGHCVSS 7.8v5.0v5.0.1+9 more2017-03-08
CVE-2017-0478 [HIGH] CVE-2017-0478: A remote code execution vulnerability in the Framesequence library could enable an attacker using a
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2017-0405P3HIGHCVSS 7.8v7.0v7.1.0+1 more2017-02-08
CVE-2017-0405 [HIGH] CWE-119 CVE-2017-0405: A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially c
A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Surfaceflinger process. Product: Android. Versions: 7.0, 7.1.1. Android
nvd
CVE-2015-3875P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3875 [CRITICAL] CWE-119 CVE-2015-3875: libutils in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a
libutils in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22952485.
nvd
CVE-2018-9498P3HIGHCVSS 7.8v7.0v7.1.1+3 more2018-10-02
CVE-2018-9498 [HIGH] CWE-190 CVE-2018-9498: In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overf
In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78354855
nvd
CVE-2024-39441P3HIGHCVSS 8.4v13.0v14.0+1 more2025-02-26
CVE-2024-39441 [HIGH] CWE-200 CVE-2024-39441: In wifi display, there is a possible missing permission check. This could lead to local escalation o
In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.
nvd
CVE-2024-20053P3HIGHCVSS 8.4v12.0v13.0+1 more2024-04-01
CVE-2024-20053 [HIGH] CWE-787 CVE-2024-20053: In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to
In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.
nvd
CVE-2024-25985P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-25985 [HIGH] CWE-416 CVE-2024-25985: In bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could
In bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27236P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27236 [HIGH] CWE-843 CVE-2024-27236: In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This co
In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20029P3HIGHCVSS 8.4v13.0v14.02024-03-04
CVE-2024-20029 [HIGH] CWE-787 CVE-2024-20029: In wlan firmware, there is a possible out of bounds write due to improper input validation. This cou
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477406; Issue ID: MSV-1010.
nvd
CVE-2017-13199P3HIGHCVSS 7.5v8.0v8.12018-01-12
CVE-2017-13199 [HIGH] CWE-755 CVE-2017-13199: In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a jav
In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException later on. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-33
nvd
CVE-2017-13196P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13196 [HIGH] CWE-772 CVE-2017-13196: In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could l
In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could lead to memory leaks. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7
nvd
CVE-2015-3874P3CRITICALCVSS 10.0≤ 5.12015-10-06
CVE-2015-3874 [CRITICAL] CWE-119 CVE-2015-3874: The Sonivox components in Android before 5.1.1 LMY48T allow remote attackers to execute arbitrary co
The Sonivox components in Android before 5.1.1 LMY48T allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23335715, 23307276, and 23286323.
nvd
CVE-2019-1987P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-02-28
CVE-2019-1987 [HIGH] CWE-787 CVE-2019-1987: In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds c
In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID:
nvd