cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 8 of 339
CVE-2016-0705P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-03-03
CVE-2016-0705 [CRITICAL] CVE-2016-0705: Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.
nvd
CVE-2017-13281P3CRITICALCVSS 9.8v8.0v8.12018-04-04
CVE-2017-13281 [CRITICAL] CWE-119 CVE-2017-13281: In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an in In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71603262.
nvd
CVE-2020-0471P3CRITICALCVSS 9.8v8.0v8.1+8 more2021-01-11
CVE-2020-0471 [CRITICAL] CWE-20 CVE-2020-0471: In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into a In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a proximal attacker, with no additional execution privileges needed. User interaction is not needed fo
nvd
CVE-2011-3918P3HIGHCVSS 7.8PoC≤ 4.0.3v1.0+28 more2012-10-07
CVE-2011-3918 [HIGH] CWE-399 CVE-2011-3918: The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted application.
nvd
CVE-2022-20222P3CRITICALCVSS 9.8v12.0v12.1+1 more2022-07-13
CVE-2022-20222 [CRITICAL] CWE-787 CVE-2022-20222: In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds ch In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-228078096
nvd
CVE-2023-21130P3CRITICALCVSS 9.8v13.0vAndroid-132023-06-15
CVE-2023-21130 [CRITICAL] CWE-125 CVE-2023-21130: In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due t In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-273502002
nvd
CVE-2023-40078P3CRITICALCVSS 9.8v14.0v142023-12-04
CVE-2023-40078 [CRITICAL] CWE-787 CVE-2023-40078: In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20951P3CRITICALCVSS 9.8v11.0v12.0+3 more2023-03-24
CVE-2023-20951 [CRITICAL] CWE-787 CVE-2023-20951: In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missi In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258652631
nvd
CVE-2023-21403P3CRITICALCVSS 9.8vAndroid SoC2023-12-04
CVE-2023-21403 [CRITICAL] CVE-2023-21403: In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaugh In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35690P3CRITICALCVSS 9.8vAndroid SoC2023-12-04
CVE-2023-35690 [CRITICAL] CVE-2023-35690: In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21402P3CRITICALCVSS 9.8vAndroid SoC2023-12-04
CVE-2023-21402 [CRITICAL] CVE-2023-21402: In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input vali In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29756P3CRITICALCVSS 9.8vAndroid kernel2024-04-05
CVE-2024-29756 [CRITICAL] CWE-121 CVE-2024-29756: In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This c In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2014-7911P3HIGHCVSS 7.2≤ 4.4.4v1.0+41 more2014-12-15
CVE-2014-7911 [HIGH] CWE-264 CVE-2014-7911: luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deserialization will result in an object that met the requirements for serialization, which allows attackers to execute arbitrary code via a crafted finalize method for a serialized object in an ArrayMap Parcel w
nvd
CVE-2026-0073P3HIGHCVSS 8.8v14.0v15.0+5 more2026-05-04
CVE-2026-0073 [HIGH] CWE-303 CVE-2026-0073: In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authenticatio In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0022P3HIGHCVSS 8.8v8.0v8.1+3 more2020-02-13
CVE-2020-0022 [HIGH] CWE-682 CVE-2020-0022: In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Andr
nvd
CVE-2016-8418P3CRITICALCVSS 9.8≤ 6.0.12017-02-08
CVE-2016-8418 [CRITICAL] CWE-284 CVE-2016-8418: A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker t A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Product: Android. Versions: N/A. Android ID: A-32652894. References: QC-CR#1077457
nvd
CVE-2018-9583P3CRITICALCVSS 9.8v7.0v7.1.1+4 more2019-02-11
CVE-2018-9583 [CRITICAL] CWE-787 CVE-2018-9583: In bta_ag_parse_cmer of bta_ag_cmd.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, And In bta_ag_parse_cmer of bta_ag_cmd.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploita
nvd
CVE-2021-39623P3CRITICALCVSS 9.8v9.0v10.0+3 more2022-01-14
CVE-2021-39623 [CRITICAL] CWE-787 CVE-2021-39623: In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect b In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-19410534
nvd
CVE-2019-2130P3CRITICALCVSS 9.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2130 [CRITICAL] CWE-843 CVE-2019-2130: In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This could lead to escalation of privilege from a malicious proxy configuration with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-
nvd
CVE-2017-13284P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13284 [CRITICAL] CWE-20 CVE-2017-13284: In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1.
nvd
Google Android vulnerabilities | cvebase