Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 64 of 339
CVE-2017-0406P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-02-08
CVE-2017-0406 [HIGH] CWE-119 CVE-2017-0406: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. V
nvd
CVE-2017-0407P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-02-08
CVE-2017-0407 [HIGH] CWE-119 CVE-2017-0407: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. V
nvd
CVE-2022-20111P3HIGHCVSS 8.4v9.0v10.0+2 more2022-05-03
CVE-2022-20111 [HIGH] CWE-755 CVE-2022-20111: In ion, there is a possible use after free due to incorrect error handling. This could lead to local
In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366069; Issue ID: ALPS06366069.
nvd
CVE-2017-0543P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-04-07
CVE-2017-0543 [HIGH] CWE-119 CVE-2017-0543: A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a spec
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0
nvd
CVE-2017-0539P3HIGHCVSS 7.8v5.0v5.0.1+9 more2017-04-07
CVE-2017-0539 [HIGH] CWE-119 CVE-2017-0539: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2017-0542P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-04-07
CVE-2017-0542 [HIGH] CWE-119 CVE-2017-0542: A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a spec
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0
nvd
CVE-2017-0538P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-04-07
CVE-2017-0538 [HIGH] CWE-119 CVE-2017-0538: A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a spec
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0
nvd
CVE-2017-0591P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-05-12
CVE-2017-0591 [HIGH] CWE-119 CVE-2017-0591: A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a spec
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0
nvd
CVE-2017-0590P3HIGHCVSS 7.8v5.0v5.0.1+10 more2017-05-12
CVE-2017-0590 [HIGH] CWE-119 CVE-2017-0590: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2017-0587P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-05-12
CVE-2017-0587 [HIGH] CWE-119 CVE-2017-0587: A remote code execution vulnerability in libmpeg2 in Mediaserver could enable an attacker using a sp
A remote code execution vulnerability in libmpeg2 in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7
nvd
CVE-2017-0592P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-05-12
CVE-2017-0592 [HIGH] CWE-119 CVE-2017-0592: A remote code execution vulnerability in FLACExtractor.cpp in libstagefright in Mediaserver could en
A remote code execution vulnerability in FLACExtractor.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Andro
nvd
CVE-2017-0589P3HIGHCVSS 7.8v5.0v5.0.1+10 more2017-05-12
CVE-2017-0589 [HIGH] CWE-119 CVE-2017-0589: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2017-0588P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-05-12
CVE-2017-0588 [HIGH] CWE-119 CVE-2017-0588: A remote code execution vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a
A remote code execution vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Ve
nvd
CVE-2018-9491P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-10-02
CVE-2018-9491 [HIGH] CWE-190 CVE-2018-9491: In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an
In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in external apps with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Androi
nvd
CVE-2018-9473P3HIGHCVSS 7.8v8.02018-10-02
CVE-2018-9473 [HIGH] CWE-190 CVE-2018-9473: In ihevcd_parse_sei_payload of ihevcd_parse_headers.c, there is a possible out-of-bounds write due t
In ihevcd_parse_sei_payload of ihevcd_parse_headers.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android ID: A-65484460
nvd
CVE-2018-9490P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-10-02
CVE-2018-9490 [HIGH] CWE-704 CVE-2018-9490: In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type co
In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0
nvd
CVE-2018-9536P3HIGHCVSS 7.8v9.02018-11-14
CVE-2018-9536 [HIGH] CWE-787 CVE-2018-9536: In numerous functions of libFDK, there are possible out of bounds writes due to incorrect bounds che
In numerous functions of libFDK, there are possible out of bounds writes due to incorrect bounds checks. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112662184
nvd
CVE-2017-13197P3HIGHCVSS 7.5v6.0v6.0.1+5 more2018-01-12
CVE-2017-13197 [HIGH] CWE-119 CVE-2017-13197: In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error. This could
In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64784973.
nvd
CVE-2017-13211P3HIGHCVSS 7.5v8.02018-01-12
CVE-2017-13211 [HIGH] CWE-400 CVE-2017-13211: In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large
In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.
nvd
CVE-2016-6699P3HIGHCVSS 7.8≤ 7.02016-12-13
CVE-2016-6699 [HIGH] CWE-119 CVE-2016-6699: A remote code execution vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11
A remote code execution vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. An
nvd