cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 61 of 339
CVE-2024-49742P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-49742 [HIGH] CWE-269 CVE-2024-49742: In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-20796P3HIGHCVSS 7.8v15.02026-01-06
CVE-2025-20796 [HIGH] CWE-1285 CVE-2025-20796: In imgsys, there is a possible out of bounds write due to improper input validation. This could lead In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID: MSV-5553.
nvd
CVE-2025-20800P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20800 [HIGH] CWE-787 CVE-2025-20800: In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead t In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267349; Issue ID: MSV-5033.
nvd
CVE-2024-29779P3HIGHCVSS 7.8vAndroid kernel2024-09-13
CVE-2024-29779 [HIGH] CWE-269 CVE-2024-29779: there is a possible escalation of privilege due to an unusual root cause. This could lead to local e there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21399P3HIGHCVSS 7.8vAndroid kernel2023-07-13
CVE-2023-21399 [HIGH] CWE-327 CVE-2023-21399: there is a possible way to bypass cryptographic assurances due to a logic error in the code. This co there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0517P3HIGHCVSS 7.5v11.0vAndroid-112021-06-21
CVE-2021-0517 [HIGH] CWE-670 CVE-2021-0517: In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state deter In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for e
nvd
CVE-2015-6617P3CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6617 [CRITICAL] CWE-119 CVE-2015-6617: Skia, as used in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01, allows remote attackers to e Skia, as used in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23648740.
nvd
CVE-2022-20516P3HIGHCVSS 7.5v13.0vAndroid-132022-12-16
CVE-2022-20516 [HIGH] CWE-191 CVE-2022-20516: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an i In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224002331
nvd
CVE-2019-9281P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9281 [HIGH] CWE-22 CVE-2019-9281: In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction requirements with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-32748076
nvd
CVE-2021-39762P3HIGHCVSS 7.5v12.1vAndroid-12L2022-03-30
CVE-2021-39762 [HIGH] CWE-190 CVE-2021-39762: In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to re In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-210625816
nvd
CVE-2021-39809P3HIGHCVSS 7.5v10.0v11.0+3 more2022-04-12
CVE-2021-39809 [HIGH] CWE-125 CVE-2021-39809: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a mis In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-20583
nvd
CVE-2022-20545P3HIGHCVSS 7.5v13.0vAndroid-132022-12-16
CVE-2022-20545 [HIGH] CWE-20 CVE-2022-20545: In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-239368697
nvd
CVE-2024-27211P3HIGHCVSS 7.7v13.0v132024-03-11
CVE-2024-27211 [HIGH] CWE-787 CVE-2024-27211: In AtiHandleAPOMsgType of ati_Main.c, there is a possible OOB write due to a missing null check. Thi In AtiHandleAPOMsgType of ati_Main.c, there is a possible OOB write due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-8507P3CRITICALCVSS 9.3v6.02015-12-08
CVE-2015-8507 [CRITICAL] CVE-2015-8507: mediaserver in Android 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or ca mediaserver in Android 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24157524, a different vulnerability than CVE-2015-6616, CVE-2015-8505, and CVE-2015-8506.
nvd
CVE-2015-8506P3CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-8506 [CRITICAL] CVE-2015-8506: mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to exec mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24441553, a different vulnerability than CVE-2015-6616, CVE-2015-8505, and CVE-2015-8507.
nvd
CVE-2022-20247P3HIGHCVSS 7.5v13.0.0vAndroid-132022-08-11
CVE-2022-20247 [HIGH] CWE-787 CVE-2022-20247: In Media, there is a possible out of bounds read due to a heap buffer overflow. This could lead to r In Media, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-229858836
nvd
CVE-2023-21027P3HIGHCVSS 7.5v13.0vAndroid-132023-03-24
CVE-2023-21027 [HIGH] CWE-287 CVE-2023-21027: In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216854451
nvd
CVE-2023-21201P3HIGHCVSS 7.5v13.0vAndroid-132023-06-28
CVE-2023-21201 [HIGH] CWE-125 CVE-2023-21201: In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a mis In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-263545186
nvd
CVE-2022-20418P3HIGHCVSS 7.5v12.0v12.1+2 more2022-10-11
CVE-2022-20418 [HIGH] CWE-125 CVE-2022-20418: In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-231986464
nvd
CVE-2023-21193P3HIGHCVSS 7.5v13.0vAndroid-132023-06-28
CVE-2023-21193 [HIGH] CWE-190 CVE-2023-21193: In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233006499
nvd
Google Android vulnerabilities | cvebase