cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 97 of 339
CVE-2017-0722P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-08-09
CVE-2017-0722 [HIGH] CVE-2017-0722: A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Androi A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37660827.
nvd
CVE-2017-0714P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-08-09
CVE-2017-0714 [HIGH] CVE-2017-0714: A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Androi A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492637.
nvd
CVE-2017-0718P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-08-09
CVE-2017-0718 [HIGH] CVE-2017-0718: A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Andro A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.
nvd
CVE-2017-0720P3HIGHCVSS 7.8v5.0v5.0.1+10 more2017-08-09
CVE-2017-0720 [HIGH] CWE-252 CVE-2017-0720: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.
nvd
CVE-2017-0719P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-08-09
CVE-2017-0719 [HIGH] CWE-772 CVE-2017-0719: A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Andro A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.
nvd
CVE-2017-0745P3HIGHCVSS 7.8v4.0v4.0.1+27 more2017-08-09
CVE-2017-0745 [HIGH] CWE-665 CVE-2017-0745: A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37079296.
nvd
CVE-2017-0700P3HIGHCVSS 7.8v7.1.1v7.1.22017-07-06
CVE-2017-0700 [HIGH] CVE-2017-0700: A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7 A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.
nvd
CVE-2017-0678P3HIGHCVSS 7.8v7.0v7.1.1+1 more2017-07-06
CVE-2017-0678 [HIGH] CVE-2017-0678: A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7. A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.
nvd
CVE-2017-0841P3HIGHCVSS 7.8v5.0.2v5.1.1+6 more2017-11-16
CVE-2017-0841 [HIGH] CWE-190 CVE-2017-0841: A remote code execution vulnerability in the Android system (libutils). Product: Android. Versions: A remote code execution vulnerability in the Android system (libutils). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37723026.
nvd
CVE-2019-20610P3HIGHCVSS 8.1v7.0v7.1.0+4 more2020-03-24
CVE-2019-20610 [HIGH] CWE-367 CVE-2019-20610: An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7 An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-13910 (April 2019).
nvd
CVE-2017-0835P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-11-16
CVE-2017-0835 [HIGH] CVE-2017-0835: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.
nvd
CVE-2017-0833P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-11-16
CVE-2017-0833 [HIGH] CVE-2017-0833: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62896384.
nvd
CVE-2017-0834P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-11-16
CVE-2017-0834 [HIGH] CWE-787 CVE-2017-0834: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63125953.
nvd
CVE-2017-0836P3HIGHCVSS 7.8v5.0.2v5.1.1+6 more2017-11-16
CVE-2017-0836 [HIGH] CWE-129 CVE-2017-0836: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64893226.
nvd
CVE-2014-9922P3HIGHCVSS 7.8≤ 7.1.12017-04-04
CVE-2014-9922 [HIGH] CWE-264 CVE-2014-9922: The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a l The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c.
nvd
CVE-2017-0832P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-11-16
CVE-2017-0832 [HIGH] CVE-2017-0832: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62887820.
nvd
CVE-2017-13250P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13250 [HIGH] CWE-787 CVE-2017-13250: In ih264d_fmt_conv_420sp_to_420p of ih264d_utils.c, there is an out of bound write due to a missing In ih264d_fmt_conv_420sp_to_420p of ih264d_utils.c, there is an out of bound write due to a missing out of bounds check because of a multiplication error. This could lead to an remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0
nvd
CVE-2018-9553P3HIGHCVSS 7.8v7.0v7.1.1+4 more2018-12-06
CVE-2018-9553 [HIGH] CWE-415 CVE-2018-9553: In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure defau In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android
nvd
CVE-2018-9551P3HIGHCVSS 7.8v9.02018-12-06
CVE-2018-9551 [HIGH] CWE-787 CVE-2018-9551: In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bound In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891548.
nvd
CVE-2017-18692P3HIGHCVSS 8.1v6.0v7.02020-04-07
CVE-2017-18692 [HIGH] CWE-362 CVE-2017-18692: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (MSM8939, MSM8996, MSM8998, An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (MSM8939, MSM8996, MSM8998, Exynos7580, Exynos8890, or Exynos8895 chipsets) software. There is a race condition, with a resultant buffer overflow, in the sec_ts touchscreen sysfs interface. The Samsung ID is SVE-2016-7501 (January 2017).
nvd
Google Android vulnerabilities | cvebase