cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 74 of 339
CVE-2023-21339P3HIGHCVSS 7.5fixed in 14.0v142023-10-30
CVE-2023-21339 [HIGH] CWE-400 CVE-2023-21339: In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource ex In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-32820P3HIGHCVSS 7.5v11.0v12.0+1 more2023-10-02
CVE-2023-32820 [HIGH] CWE-617 CVE-2023-32820: In wlan firmware, there is a possible firmware assertion due to improper input handling. This could In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.
nvd
CVE-2018-21075P3CRITICALCVSS 9.8v7.0v7.1.0+4 more2020-04-08
CVE-2018-21075 [CRITICAL] CVE-2018-21075: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. The Call+ applica An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. The Call+ application can load classes from an unintended path, leading to Code Execution. The Samsung ID is SVE-2017-10886 (April 2018).
nvd
CVE-2020-25052P3CRITICALCVSS 9.8v10.02020-08-31
CVE-2020-25052 [CRITICAL] CWE-787 CVE-2020-25052: An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to execute arbitrary code or cause a denial of service (memory corruption) because indexes are mishandled. The Samsung ID is SVE-2020-17426 (August 2020).
nvd
CVE-2024-27229P3HIGHCVSS 7.5v132024-03-11
CVE-2024-27229 [HIGH] CWE-476 CVE-2024-27229: In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref d In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-6634P3CRITICALCVSS 9.3≤ 5.12015-12-08
CVE-2015-6634 [CRITICAL] CWE-119 CVE-2015-6634: The display drivers in Android before 5.1.1 LMY48Z allow remote attackers to execute arbitrary code The display drivers in Android before 5.1.1 LMY48Z allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24163261.
nvd
CVE-2024-44101P3HIGHCVSS 7.5vAndroid kernel2024-10-25
CVE-2024-44101 [HIGH] CWE-476 CVE-2024-44101: there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This co there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-52342P3HIGHCVSS 7.5v12.0v13.0+1 more2024-04-08
CVE-2023-52342 [HIGH] CWE-248 CVE-2023-52342: In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This c In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2015-6633P3CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6633 [CRITICAL] CWE-119 CVE-2015-6633: The display drivers in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allow remote attackers The display drivers in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23987307.
nvd
CVE-2023-48398P3HIGHCVSS 7.5vAndroid kernel2023-12-08
CVE-2023-48398 [HIGH] CWE-125 CVE-2023-48398: In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possib In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2016-3745P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-07-11
CVE-2016-3745 [CRITICAL] CWE-119 CVE-2016-3745: Multiple buffer overflows in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x befo Multiple buffer overflows in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides an AudioEffect reply, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28173666.
nvd
CVE-2018-21066P3CRITICALCVSS 9.8v6.02020-04-08
CVE-2018-21066 [CRITICAL] CWE-120 CVE-2018-21066: An issue was discovered on Samsung mobile devices with M(6.0) (Exynos or MediaTek chipsets) software An issue was discovered on Samsung mobile devices with M(6.0) (Exynos or MediaTek chipsets) software. There is a buffer overflow in a Trustlet that can cause memory corruption. The Samsung ID is SVE-2018-11599 (July 2018).
nvd
CVE-2023-35652P3HIGHCVSS 7.5vAndroid kernel2023-10-11
CVE-2023-35652 [HIGH] CWE-125 CVE-2023-35652: In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2020-26607P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-10-06
CVE-2020-26607 [CRITICAL] CVE-2020-26607: An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) so An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingIntent with an empty intent is mishandled, allowing an attacker to perform a privileged action via a modified intent. The Samsung ID is SVE-2020-18418 (October 2020).
nvd
CVE-2020-25057P3CRITICALCVSS 9.8v10.02020-08-31
CVE-2020-25057 [CRITICAL] CVE-2020-25057: An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not proper An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK installations. The LG ID is LVE-SMP-200011 (July 2020).
nvd
CVE-2018-21054P3CRITICALCVSS 9.8v6.0v7.0+6 more2020-04-08
CVE-2018-21054 [CRITICAL] CWE-190 CVE-2018-21054: An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9 An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is an integer underflow with a resultant buffer overflow in eCryptFS. The Samsung ID is SVE-2017-1185
nvd
CVE-2018-14066P3CRITICALCVSS 9.8v7.0v6.02018-07-15
CVE-2018-14066 [CRITICAL] CWE-89 CVE-2018-14066: The content://wappush content provider in com.android.provider.telephony, as found in some custom RO The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fix
nvd
CVE-2025-36934P3HIGHCVSS 7.4vAndroid kernel2025-12-11
CVE-2025-36934 [HIGH] CWE-362 CVE-2025-36934: In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after f In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48630P3HIGHCVSS 7.4v14.0v15.0+5 more2026-03-02
CVE-2025-48630 [HIGH] CWE-208 CVE-2025-48630: In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due t In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32921P3HIGHCVSS 7.4vAndroid kernel2024-06-13
CVE-2024-32921 [HIGH] CWE-787 CVE-2024-32921: In lwis_initialize_transaction_fences of lwis_fence.c, there is a possible out of bounds write due t In lwis_initialize_transaction_fences of lwis_fence.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase