cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 62 of 339
CVE-2023-21197P3HIGHCVSS 7.5v13.0vAndroid-132023-06-28
CVE-2023-21197 [HIGH] CWE-125 CVE-2023-21197: In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an inco In btm_acl_process_sca_cmpl_pkt of btm_acl.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251427561
nvd
CVE-2023-21028P3HIGHCVSS 7.5v13.0vAndroid-132023-03-24
CVE-2023-21028 [HIGH] CWE-125 CVE-2023-21028: In parse_printerAttributes of ipphelper.c, there is a possible out of bounds read due to a string wi In parse_printerAttributes of ipphelper.c, there is a possible out of bounds read due to a string without a null-terminator. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-180680572
nvd
CVE-2023-20948P3HIGHCVSS 7.5v12.0v12.1+2 more2023-02-28
CVE-2023-20948 [HIGH] CWE-125 CVE-2023-20948: In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap In dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-230630526
nvd
CVE-2023-48403P3HIGHCVSS 7.5vAndroid kernel2023-12-08
CVE-2023-48403 [HIGH] CWE-787 CVE-2023-48403: In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buff In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure if the attacker is able to observe the behavior of the subsequent switch conditional with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0081P3HIGHCVSS 7.5v12.0v12.1+8 more2025-08-26
CVE-2025-0081 [HIGH] CWE-457 CVE-2025-0081: In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a cra In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21347P3HIGHCVSS 7.5fixed in 14.0v142023-10-30
CVE-2023-21347 [HIGH] CWE-125 CVE-2023-21347: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-35550P3CRITICALCVSS 9.8v8.0v8.1+3 more2020-12-18
CVE-2020-35550 [CRITICAL] CVE-2020-35550: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-17888 (December 2020).
nvd
CVE-2023-21233P3HIGHCVSS 7.5v11.0v112023-08-14
CVE-2023-21233 [HIGH] CWE-908 CVE-2023-21233: In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-21049P3CRITICALCVSS 9.8v7.0v7.1.0+4 more2020-04-08
CVE-2018-21049 [CRITICAL] CWE-787 CVE-2018-21049: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is an arbitrary memory write in a Trustlet because a secure driver allows access to sensitive APIs. The Samsung ID is SVE-2018-12881 (November 2018).
nvd
CVE-2024-40675P3HIGHCVSS 7.5v12.0v12.1+6 more2025-01-28
CVE-2024-40675 [HIGH] CWE-835 CVE-2024-40675: In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validati In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20129P3HIGHCVSS 7.5v13.0v14.0+1 more2024-12-02
CVE-2024-20129 [HIGH] CWE-125 CVE-2024-20129: In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2025.
nvd
CVE-2024-20127P3HIGHCVSS 7.5v13.0v14.0+1 more2024-12-02
CVE-2024-20127 [HIGH] CWE-125 CVE-2024-20127: In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2023.
nvd
CVE-2024-20128P3HIGHCVSS 7.5v13.0v14.0+1 more2024-12-02
CVE-2024-20128 [HIGH] CWE-125 CVE-2024-20128: In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2024.
nvd
CVE-2018-9456P3HIGHCVSS 7.5v7.0v7.1.1+7 more2024-11-19
CVE-2018-9456 [HIGH] CWE-125 CVE-2018-9456: In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40104P3HIGHCVSS 7.5v11.0v12.0+6 more2024-02-15
CVE-2023-40104 [HIGH] CWE-295 CVE-2023-40104: In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographi In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21265P3HIGHCVSS 7.5v11.0v12.0+6 more2023-08-14
CVE-2023-21265 [HIGH] CWE-295 CVE-2023-21265: In multiple locations, there are root CA certificates which need to be disabled. This could lead to In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35656P3HIGHCVSS 7.5vAndroid kernel2023-10-18
CVE-2023-35656 [HIGH] CWE-125 CVE-2023-35656: In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due t In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35663P3HIGHCVSS 7.5vAndroid kernel2023-10-18
CVE-2023-35663 [HIGH] CWE-125 CVE-2023-35663: In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bou In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9381P3HIGHCVSS 7.5v8.12024-12-02
CVE-2018-9381 [HIGH] CWE-908 CVE-2018-9381: In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to un In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9364P3HIGHCVSS 7.5vSoCVersion2024-11-19
CVE-2018-9364 [HIGH] CWE-203 CVE-2018-9364: In the LG LAF component, there is a special command that allowed modification of certain partitions. In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase