Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 59 of 483
CVE-2024-0153HIGHCVSS 7.82024-07-01
CVE-2024-0153 [HIGH] CVE-2024-0153: Mali Android Security Bulletin 2024-07-01 CVE: CVE-2024-0153 Severity: HIGH Component: Mali References: A-302570828 *
android
CVE-2024-23380HIGHCVSS 8.42024-07-01
CVE-2024-23380 [HIGH] CVE-2024-23380: Display Android Security Bulletin 2024-07-01 CVE: CVE-2024-23380 Severity: HIGH Component: Display References: A-332315362 QC-CR#3690718 [2]
android
CVE-2024-23368HIGHCVSS 7.82024-07-01
CVE-2024-23368 [HIGH] CVE-2024-23368: Kernel Android Security Bulletin 2024-07-01 CVE: CVE-2024-23368 Severity: HIGH Component: Kernel References: A-332315224 QC-CR#3522299
android
CVE-2024-21465HIGHCVSS 7.82024-07-01
CVE-2024-21465 [HIGH] CVE-2024-21465: Closed-source component Android Security Bulletin 2024-07-01 CVE: CVE-2024-21465 Severity: HIGH Component: Closed-source component References: A-318393702 *
android
CVE-2024-21469HIGHCVSS 7.32024-07-01
CVE-2024-21469 [HIGH] CVE-2024-21469: Closed-source component Android Security Bulletin 2024-07-01 CVE: CVE-2024-21469 Severity: HIGH Component: Closed-source component References: A-318393825 *
android
CVE-2024-23372HIGHCVSS 8.42024-07-01
CVE-2024-23372 [HIGH] CVE-2024-23372: Display Android Security Bulletin 2024-07-01 CVE: CVE-2024-23372 Severity: HIGH Component: Display References: A-332315102 QC-CR#3692589 [2]
android
CVE-2024-20076HIGHCVSS 7.52024-07-01
CVE-2024-20076 [HIGH] CVE-2024-20076: Modem Android Security Bulletin 2024-07-01 CVE: CVE-2024-20076 Severity: HIGH Component: Modem References: A-338887100 MOLY01297806 *
android
CVE-2024-21462HIGHCVSS 7.12024-07-01
CVE-2024-21462 [HIGH] CVE-2024-21462: Closed-source component Android Security Bulletin 2024-07-01 CVE: CVE-2024-21462 Severity: HIGH Component: Closed-source component References: A-318394116 *
android
CVE-2024-21460HIGHCVSS 7.12024-07-01
CVE-2024-21460 [HIGH] CVE-2024-21460: Closed-source component Android Security Bulletin 2024-07-01 CVE: CVE-2024-21460 Severity: HIGH Component: Closed-source component References: A-318393435 *
android
CVE-2024-20077HIGHCVSS 7.52024-07-01
CVE-2024-20077 [HIGH] CVE-2024-20077: Modem Android Security Bulletin 2024-07-01 CVE: CVE-2024-20077 Severity: HIGH Component: Modem References: A-338887097 MOLY01297807 *
android
CVE-2024-23373HIGHCVSS 8.42024-07-01
CVE-2024-23373 [HIGH] CVE-2024-23373: Display Android Security Bulletin 2024-07-01 CVE: CVE-2024-23373 Severity: HIGH Component: Display References: A-332315050 QC-CR#3692564 [2]
android
CVE-2024-20079MEDIUMCVSS 6.7v13.0v14.02024-07-01
CVE-2024-20079 [MEDIUM] CWE-787 CVE-2024-20079: In gnss service, there is a possible out of bounds write due to improper input validation. This coul In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: MSV-1491.
nvd
CVE-2024-39427MEDIUMCVSS 4.4v12.0v13.0+1 more2024-07-01
CVE-2024-39427 [MEDIUM] CWE-787 CVE-2024-39427: In trusty service, there is a possible out of bounds write due to a missing bounds check. This could In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2024-39429MEDIUMCVSS 6.2v12.02024-07-01
CVE-2024-39429 [MEDIUM] CWE-787 CVE-2024-39429: In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2024-39428MEDIUMCVSS 4.4v12.0v13.0+1 more2024-07-01
CVE-2024-39428 [MEDIUM] CWE-787 CVE-2024-39428: In trusty service, there is a possible out of bounds write due to a missing bounds check. This could In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2024-39430MEDIUMCVSS 6.2v12.02024-07-01
CVE-2024-39430 [MEDIUM] CWE-787 CVE-2024-39430: In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2024-20081MEDIUMCVSS 6.7v13.0v14.02024-07-01
CVE-2024-20081 [MEDIUM] CWE-787 CVE-2024-20081: In gnss service, there is a possible out of bounds write due to improper input validation. This coul In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412.
nvd
CVE-2024-32911CRITICALCVSS 9.8vAndroid kernel2024-06-13
CVE-2024-32911 [CRITICAL] CWE-327 CVE-2024-32911: There is a possible escalation of privilege due to improperly used crypto. This could lead to remote There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29786CRITICALCVSS 9.8vAndroid kernel2024-06-13
CVE-2024-29786 [CRITICAL] CWE-787 CVE-2024-29786: In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write d In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32905CRITICALCVSS 9.8vAndroid kernel2024-06-13
CVE-2024-32905 [CRITICAL] CWE-787 CVE-2024-32905: In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incor In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd