cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 65 of 339
CVE-2018-9550P3HIGHCVSS 7.8v9.02018-12-06
CVE-2018-9550 [HIGH] CWE-787 CVE-2018-9550: In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing boun In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112660981.
nvd
CVE-2018-9527P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-11-14
CVE-2018-9527 [HIGH] CWE-787 CVE-2018-9527: In vorbis_book_decodev_set of codebook.c there is a possible out of bounds write due to missing boun In vorbis_book_decodev_set of codebook.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android
nvd
CVE-2019-20613P3HIGHCVSS 8.1v7.0v7.1.0+4 more2020-03-24
CVE-2019-20613 [HIGH] CWE-89 CVE-2019-20613: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-bas An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is SVE-2018-13452 (March 2019).
nvd
CVE-2018-9549P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-12-06
CVE-2018-9549 [HIGH] CWE-787 CVE-2018-9549: In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-11
nvd
CVE-2019-2176P3HIGHCVSS 7.8v8.0v8.1+2 more2019-09-05
CVE-2019-2176 [HIGH] CWE-787 CVE-2019-2176: In ihevcd_parse_buffering_period_sei of ihevcd_parse_headers.c in Android 8.0, 8.1 and 9, there is a In ihevcd_parse_buffering_period_sei of ihevcd_parse_headers.c in Android 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2019-2108P3HIGHCVSS 7.8v10.0vAndroid-102019-09-05
CVE-2019-2108 [HIGH] CWE-787 CVE-2019-2108: In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due t In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2017-13191P3HIGHCVSS 7.5v5.1.1v6.0+6 more2018-01-12
CVE-2017-13191 [HIGH] CWE-835 CVE-2017-13191: In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete fra In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0,
nvd
CVE-2021-0393P3HIGHCVSS 7.8v8.1v9.0+3 more2021-03-10
CVE-2021-0393 [HIGH] CWE-190 CVE-2021-0393: In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if an attacker can supply a malicious PAC file, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1
nvd
CVE-2014-7920P3CRITICALCVSS 9.8v2.2v2.2.1+37 more2017-04-13
CVE-2014-7920 [CRITICAL] CWE-264 CVE-2014-7920: mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This i mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.
nvd
CVE-2021-0673P3HIGHCVSS 7.8v10.0v11.0+1 more2021-12-17
CVE-2021-0673 [HIGH] CWE-862 CVE-2021-0673: In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05977326; Issue ID: ALPS05977326.
nvd
CVE-2011-2344P3CRITICALCVSS 10.0v2.1v2.2+6 more2011-07-08
CVE-2011-2344 [CRITICAL] CWE-310 CVE-2011-2344: Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.
nvd
CVE-2021-0675P3HIGHCVSS 7.8v8.1v9.0+2 more2021-12-15
CVE-2021-0675 [HIGH] CWE-787 CVE-2021-0675: In alac decoder, there is a possible out of bounds write due to an incorrect bounds check. This coul In alac decoder, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06064258; Issue ID: ALPS06064258.
nvd
CVE-2017-13278P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13278 [HIGH] CWE-416 CVE-2017-13278: In MediaPlayerService::Client::notify of MediaPlayerService.cpp, there is a possible use after free. In MediaPlayerService::Client::notify of MediaPlayerService.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70546581.
nvd
CVE-2019-9254P3HIGHCVSS 7.8v10.0vAndroid-102019-09-05
CVE-2019-9254 [HIGH] CWE-20 CVE-2019-9254: In readArgumentList of zygote.java in Android 10, there is a possible command injection due to impro In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0130P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0130 [HIGH] CWE-20 CVE-2020-0130: In screencap, there is a possible command injection due to improper input validation. This could lea In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123230379
nvd
CVE-2020-0082P3HIGHCVSS 7.8v10.0vAndroid-102020-04-17
CVE-2020-0082 [HIGH] CWE-502 CVE-2020-0082: In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary inten In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead to local escalation of privilege to system_server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140417434
nvd
CVE-2020-0037P3HIGHCVSS 7.5v8.0v8.1+3 more2020-03-10
CVE-2020-0037 [HIGH] CWE-125 CVE-2020-0037: In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds read due to a missing bou In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143106
nvd
CVE-2020-0039P3HIGHCVSS 7.5v8.0v8.1+3 more2020-03-10
CVE-2020-0039 [HIGH] CWE-125 CVE-2020-0039: In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missi In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143155861
nvd
CVE-2020-0038P3HIGHCVSS 7.5v8.0v8.1+3 more2020-03-10
CVE-2020-0038 [HIGH] CWE-125 CVE-2020-0038: In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missi In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143109193
nvd
CVE-2019-2051P3HIGHCVSS 7.5v7.0v7.1.1+5 more2019-05-08
CVE-2019-2051 [HIGH] CWE-20 CVE-2019-2051: In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This c In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when processing a proxy auto config file with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-
nvd
Google Android vulnerabilities | cvebase