cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 76 of 339
CVE-2017-0470P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0470 [HIGH] CWE-119 CVE-2017-0470: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0467P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0467 [HIGH] CWE-119 CVE-2017-0467: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0408P3HIGHCVSS 7.8v7.1.12017-02-08
CVE-2017-0408 [HIGH] CVE-2017-0408: A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted f A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 7.1.1. Android ID: A-32769670.
nvd
CVE-2017-0409P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-02-08
CVE-2017-0409 [HIGH] CVE-2017-0409: A remote code execution vulnerability in libstagefright could enable an attacker using a specially c A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID:
nvd
CVE-2016-3863P3HIGHCVSS 7.8v4.0v4.0.1+21 more2016-09-11
CVE-2016-3863 [HIGH] CWE-284 CVE-2016-3863: Multiple stack-based buffer overflows in the AVCC reassembly implementation in Utils.cpp in libstage Multiple stack-based buffer overflows in the AVCC reassembly implementation in Utils.cpp in libstagefright in MediaMuxer in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allow remote attackers to execute arbitrary code via a crafted media file, aka internal bug 29161888.
nvd
CVE-2018-9531P3HIGHCVSS 7.8v9.02018-11-14
CVE-2018-9531 [HIGH] CWE-787 CVE-2018-9531: In AudioSpecificConfig_Parse of tpdec_asc.cpp, there is a possible out-of-bounds write due to a miss In AudioSpecificConfig_Parse of tpdec_asc.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112661641
nvd
CVE-2017-13248P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13248 [HIGH] CWE-787 CVE-2017-13248: In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due t In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due to a missing bounds check. This could lead to an remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-7034961
nvd
CVE-2017-13249P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13249 [HIGH] CWE-787 CVE-2017-13249: In impeg2d_api_set_display_frame of impeg2d_api_main.c, there is an out of bound write due to a miss In impeg2d_api_set_display_frame of impeg2d_api_main.c, there is an out of bound write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70399408.
nvd
CVE-2019-2094P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2094 [HIGH] CWE-787 CVE-2019-2094: In parseMPEGCCData of NuPlayerCCDecoder.cpp, there is a possible out of bounds write due to missing In parseMPEGCCData of NuPlayerCCDecoder.cpp, there is a possible out of bounds write due to missing bounds checks. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Andr
nvd
CVE-2018-9577P3HIGHCVSS 7.8v9.02018-12-07
CVE-2018-9577 [HIGH] CWE-787 CVE-2018-9577: In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715937.
nvd
CVE-2018-9575P3HIGHCVSS 7.8v9.02018-12-07
CVE-2018-9575 [HIGH] CWE-787 CVE-2018-9575: In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds wri In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619387.
nvd
CVE-2018-9574P3HIGHCVSS 7.8v9.02018-12-07
CVE-2018-9574 [HIGH] CWE-787 CVE-2018-9574: In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bound In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619337.
nvd
CVE-2018-9573P3HIGHCVSS 7.8v9.02018-12-07
CVE-2018-9573 [HIGH] CWE-787 CVE-2018-9573: In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due t In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116467350.
nvd
CVE-2018-9576P3HIGHCVSS 7.8v9.02018-12-07
CVE-2018-9576 [HIGH] CWE-787 CVE-2018-9576: In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bo In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715245.
nvd
CVE-2018-9362P3HIGHCVSS 7.5v6.0v6.0.1+5 more2018-11-06
CVE-2018-9362 [HIGH] CWE-20 CVE-2018-9362: In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-
nvd
CVE-2021-25485P3HIGHCVSS 8.0v10.0v11.02021-10-06
CVE-2021-25485 [HIGH] CWE-20 CVE-2021-25485: Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attac Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.
nvd
CVE-2020-0096P3HIGHCVSS 7.8v8.0v8.1+2 more2020-05-14
CVE-2020-0096 [HIGH] CVE-2020-0096: In startActivities of ActivityStartController.java, there is a possible escalation of privilege due In startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-145669109
nvd
CVE-2018-9590P3HIGHCVSS 7.5v7.0v7.1.1+4 more2019-02-11
CVE-2018-9590 [HIGH] CWE-125 CVE-2018-9590: In add_attr of sdp_discovery.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8. In add_attr of sdp_discovery.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-11590004
nvd
CVE-2018-9591P3HIGHCVSS 7.5v7.0v7.1.1+4 more2019-02-11
CVE-2018-9591 [HIGH] CWE-125 CVE-2018-9591: In bta_hh_ctrl_dat_act of bta_hh_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, A In bta_hh_ctrl_dat_act of bta_hh_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A
nvd
CVE-2018-9592P3HIGHCVSS 7.5v7.0v7.1.1+4 more2019-02-11
CVE-2018-9592 [HIGH] CWE-125 CVE-2018-9592: In mca_ccb_hdl_rsp of mca_cact.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android In mca_ccb_hdl_rsp of mca_cact.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-11631
nvd
Google Android vulnerabilities | cvebase