cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 73 of 339
CVE-2021-1002P3HIGHCVSS 7.5v12.0vAndroid-122021-12-15
CVE-2021-1002 [HIGH] CWE-125 CVE-2021-1002: In WT_Interpolate of eas_wtengine.c, there is a possible out of bounds read due to a missing bounds In WT_Interpolate of eas_wtengine.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194533433
nvd
CVE-2020-0460P3HIGHCVSS 7.5v11.0vAndroid-112020-12-14
CVE-2020-0460 [HIGH] CWE-287 CVE-2020-0460: In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly inst In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-163413737
nvd
CVE-2022-32589P3HIGHCVSS 7.5v11.0v12.02022-10-07
CVE-2022-32589 [HIGH] CWE-404 CVE-2022-32589: In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. Th In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07030600; Issue ID: ALPS07030600.
nvd
CVE-2022-32591P3HIGHCVSS 7.5v11.0v12.02022-10-07
CVE-2022-32591 [HIGH] CWE-20 CVE-2022-32591: In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07257259; Issue ID: ALPS07257259.
nvd
CVE-2016-8411P3CRITICALCVSS 9.8≤ 7.1.12017-01-27
CVE-2016-8411 [CRITICAL] CWE-119 CVE-2016-8411: Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions th Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. References: QC CR#912775.
nvd
CVE-2019-20567P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20567 [CRITICAL] CWE-787 CVE-2019-20567: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. A up_parm heap overflow leads to code execution in the bootloader. The Samsung ID is SVE-2019-14993 (September 2019).
nvd
CVE-2020-27055P3HIGHCVSS 7.5v11.0vAndroid-112020-12-15
CVE-2020-27055 [HIGH] CWE-311 CVE-2020-27055: In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigCon In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there is a possible insecure WiFi configuration due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An
nvd
CVE-2016-2418P3CRITICALCVSS 9.8v6.0v6.0.12016-04-18
CVE-2016-2418 [CRITICAL] CWE-119 CVE-2016-2418: media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem acce
nvd
CVE-2016-5300P3HIGHCVSS 7.5v4.4.4v5.0.2+3 more2016-06-16
CVE-2016-5300 [HIGH] CVE-2016-5300: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows contex The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
nvd
CVE-2022-21757P3HIGHCVSS 7.5v11.0v12.02022-06-06
CVE-2022-21757 [HIGH] CWE-354 CVE-2022-21757: In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06468894; Issue ID: ALPS06468894.
nvd
CVE-2022-20308P3HIGHCVSS 7.5v13.0vAndroid-132022-08-12
CVE-2022-20308 [HIGH] CVE-2022-20308: In hostapd, there is a possible insecure configuration due to an insecure default value. This could In hostapd, there is a possible insecure configuration due to an insecure default value. This could lead to remote denial of service of the wifi hotspot with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-197874458
nvd
CVE-2015-8505P3CRITICALCVSS 9.3≤ 5.12015-12-08
CVE-2015-8505 [CRITICAL] CVE-2015-8505: mediaserver in Android before 5.1.1 LMY48Z allows remote attackers to execute arbitrary code or caus mediaserver in Android before 5.1.1 LMY48Z allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 17769851, a different vulnerability than CVE-2015-6616, CVE-2015-8506, and CVE-2015-8507.
nvd
CVE-2023-21186P3HIGHCVSS 7.5v13.0vAndroid-132023-06-28
CVE-2023-21186 [HIGH] CWE-125 CVE-2023-21186: In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. Thi In LogResponse of Dns.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261079188
nvd
CVE-2023-48416P3HIGHCVSS 7.5vAndroid kernel2023-12-08
CVE-2023-48416 [HIGH] CWE-476 CVE-2023-48416: In multiple locations, there is a possible null dereference due to a missing null check. This could In multiple locations, there is a possible null dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20690P3HIGHCVSS 7.5v11.0v12.02023-07-04
CVE-2023-20690 [HIGH] CWE-190 CVE-2023-20690: In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remo In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ALPS07664735.
nvd
CVE-2023-20691P3HIGHCVSS 7.5v11.0v12.02023-07-04
CVE-2023-20691 [HIGH] CWE-190 CVE-2023-20691: In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remo In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664731; Issue ID: ALPS07664731.
nvd
CVE-2023-20692P3HIGHCVSS 7.5v11.02023-07-04
CVE-2023-20692 [HIGH] CWE-755 CVE-2023-20692: In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to re In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664720; Issue ID: ALPS07664720.
nvd
CVE-2023-20689P3HIGHCVSS 7.5v11.02023-07-04
CVE-2023-20689 [HIGH] CWE-190 CVE-2023-20689: In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remo In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664741; Issue ID: ALPS07664741.
nvd
CVE-2023-20693P3HIGHCVSS 7.5v11.0v12.02023-07-04
CVE-2023-20693 [HIGH] CWE-190 CVE-2023-20693: In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to re In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664711; Issue ID: ALPS07664711.
nvd
CVE-2023-21391P3HIGHCVSS 7.5fixed in 14.0v142023-10-30
CVE-2023-21391 [HIGH] CWE-20 CVE-2023-21391: In Messaging, there is a possible way to disable the messaging application due to improper input val In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase