Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 95 of 339
CVE-2019-20622P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20622 [CRITICAL] CWE-787 CVE-2019-20622: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets)
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband stack overflow. The Samsung ID is SVE-2018-13188 (February 2019).
nvd
CVE-2020-10848P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-03-24
CVE-2020-10848 [CRITICAL] CWE-119 CVE-2020-10848: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos 9810 chip
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos 9810 chipsets) software. Arbitrary memory mapping exists in TEE. The Samsung ID is SVE-2019-16665 (February 2020).
nvd
CVE-2019-20545P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20545 [CRITICAL] CWE-120 CVE-2019-20545: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos chipsets) software.
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos chipsets) software. A buffer overflow in the HDCP Trustlet affects secure TEEGRIS memory. The Samsung ID is SVE-2019-15283 (November 2019).
nvd
CVE-2024-20089P3HIGHCVSS 7.5v13.0v14.02024-09-02
CVE-2024-20089 [HIGH] CWE-703 CVE-2024-20089: In wlan, there is a possible denial of service due to incorrect error handling. This could lead to r
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
nvd
CVE-2024-32924P3HIGHCVSS 7.5vAndroid kernel2024-06-13
CVE-2024-32924 [HIGH] CVE-2024-32924: In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a l
In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-26687P3CRITICALCVSS 9.8v8.0v8.1+2 more2021-02-04
CVE-2021-26687 [CRITICAL] CVE-2021-26687: An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In prel
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (February 2021).
nvd
CVE-2021-26689P3CRITICALCVSS 9.8v8.0v8.1+2 more2021-02-04
CVE-2021-26689 [CRITICAL] CWE-416 CVE-2021-26689: An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).
nvd
CVE-2023-21227P3HIGHCVSS 7.5vAndroid SoC2023-12-04
CVE-2023-21227 [HIGH] CVE-2023-21227: In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclo
In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclosure. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-44100P3HIGHCVSS 7.5fixed in 2024-10-05vAndroid kernel2024-10-25
CVE-2024-44100 [HIGH] CWE-276 CVE-2024-44100: Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem compone
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
nvd
CVE-2020-28340P3CRITICALCVSS 9.8v8.0v8.1+3 more2020-11-08
CVE-2020-28340 [CRITICAL] CVE-2020-28340: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-18546 (November 2020).
nvd
CVE-2020-10836P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-03-24
CVE-2020-10836 [CRITICAL] CWE-125 CVE-2020-10836: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets)
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The Widevine Trustlet allows read and write operations on arbitrary memory locations. The Samsung ID is SVE-2019-15873 (February 2020).
nvd
CVE-2020-25061P3CRITICALCVSS 9.8v9.0v10.02020-08-31
CVE-2020-25061 [CRITICAL] CVE-2020-25061: An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. l
An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows property overwrites. The LG ID is LVE-SMP-200016 (July 2020).
nvd
CVE-2019-20778P3CRITICALCVSS 9.8v7.0v7.1+4 more2020-04-17
CVE-2019-20778 [CRITICAL] CWE-20 CVE-2019-20778: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 softwa
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Backup subsystem does not properly restrict operations or validate their input. The LG ID is LVE-SMP-190004 (June 2019).
nvd
CVE-2018-21087P3CRITICALCVSS 9.8v5.0v5.0.1+10 more2020-04-08
CVE-2018-21087 [CRITICAL] CWE-787 CVE-2018-21087: An issue was discovered on Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software. There is
An issue was discovered on Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software. There is a vnswap heap-based buffer overflow via the store function, with resultant privilege escalation. The Samsung ID is SVE-2017-10599 (January 2018).
nvd
CVE-2019-20548P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2019-20548 [CRITICAL] CWE-120 CVE-2019-20548: An issue was discovered on Samsung mobile devices with P(9.0) devices (Qualcomm chipsets) software.
An issue was discovered on Samsung mobile devices with P(9.0) devices (Qualcomm chipsets) software. There is a buffer overflow in the bootloader. The Samsung ID is SVE-2019-15399 (November 2019).
nvd
CVE-2020-35551P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-12-18
CVE-2020-35551 [CRITICAL] CVE-2020-35551: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets)
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CVE-2020-13799. The Samsung ID is SVE-2020-18100 (December 2020).
nvd
CVE-2022-20244P3HIGHCVSS 7.5v13.0.0vAndroid-132022-08-11
CVE-2022-20244 [HIGH] CWE-787 CVE-2022-20244: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if more than 100 bluetooth devices have been connected with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201083240
nvd
CVE-2015-3849P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3849 [CRITICAL] CWE-264 CVE-2015-3849: The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android be
The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attackers to execute arbitrary code via an application that sends a crafted message to a service, aka internal bug 21585255.
nvd
CVE-2024-29740P3HIGHCVSS 7.4vAndroid kernel2024-04-05
CVE-2024-29740 [HIGH] CWE-787 CVE-2024-29740: In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. Th
In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-44098P3HIGHCVSS 7.4vAndroid kernel2024-10-25
CVE-2024-44098 [HIGH] CWE-415 CVE-2024-44098: In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation d
In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd