cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 98 of 339
CVE-2016-6702P3HIGHCVSS 7.8v4.0v4.0.1+18 more2016-11-25
CVE-2016-6702 [HIGH] CWE-284 CVE-2016-6702: A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, an A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjp
nvd
CVE-2021-0433P3HIGHCVSS 8.0v8.1v9.0+3 more2021-04-13
CVE-2021-0433 [HIGH] CWE-1021 CVE-2021-0433: In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairi In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege and pairing malicious devices with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:
nvd
CVE-2017-13277P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13277 [HIGH] CWE-787 CVE-2017-13277: In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bo In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-72165027.
nvd
CVE-2016-6703P3HIGHCVSS 7.8≤ 6.0.1v4.0+20 more2016-11-25
CVE-2016-6703 [HIGH] CWE-284 CVE-2016-6703: A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0 A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker using a specially crafted payload to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote cod
nvd
CVE-2017-0382P3HIGHCVSS 7.8v5.0v5.0.1+8 more2017-01-12
CVE-2017-0382 [HIGH] CVE-2017-0382: A remote code execution vulnerability in the Framesequence library could enable an attacker using a A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1,
nvd
CVE-2016-6701P3HIGHCVSS 7.8≤ 7.02016-11-25
CVE-2016-6701 [HIGH] CWE-119 CVE-2016-6701: A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an at A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637.
nvd
CVE-2017-0429P3HIGHCVSS 7.8≤ 7.1.12017-02-08
CVE-2017-0429 [HIGH] CWE-787 CVE-2017-0429: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0428P3HIGHCVSS 7.8≤ 7.1.12017-02-08
CVE-2017-0428 [HIGH] CWE-416 CVE-2017-0428: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious appl An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Ve
nvd
CVE-2017-0638P3HIGHCVSS 7.8v7.1.1v7.1.22017-06-14
CVE-2017-0638 [HIGH] CWE-787 CVE-2017-0638: A remote code execution vulnerability in System UI component could enable an attacker using a specia A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary code execution in an unprivileged process. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36368
nvd
CVE-2018-9570P3HIGHCVSS 7.8v9.02018-12-07
CVE-2018-9570 [HIGH] CWE-787 CVE-2018-9570: In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-115375616.
nvd
CVE-2018-9455P3HIGHCVSS 7.5v6.0v6.0.1+5 more2018-11-06
CVE-2018-9455 [HIGH] CWE-125 CVE-2018-9455: In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Androi
nvd
CVE-2016-6768P3HIGHCVSS 7.8v5.0v5.0.1+7 more2017-01-12
CVE-2016-6768 [HIGH] CWE-284 CVE-2016-6768: A remote code execution vulnerability in the Framesequence library could enable an attacker using a A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2
nvd
CVE-2021-0481P3HIGHCVSS 7.8v8.1v9.0+3 more2021-06-11
CVE-2021-0481 [HIGH] CWE-20 CVE-2021-0481: In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized file In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID
nvd
CVE-2016-5344P3CRITICALCVSS 9.8≤ 7.02016-08-30
CVE-2016-5344 [CRITICAL] CWE-190 CVE-2016-5344: Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovati Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified other impact via a large size value, related to mdss_compat_utils.c, mdss_fb.c, and mdss_rotator.c.
nvd
CVE-2021-0302P3HIGHCVSS 7.8v8.1v9.0+2 more2021-02-10
CVE-2021-0302 [HIGH] CWE-1021 CVE-2021-0302: In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This co In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-155287782
nvd
CVE-2017-13276P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13276 [HIGH] CWE-119 CVE-2017-13276: In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a possible stack buffer overflow due to a In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a possible stack buffer overflow due to a missing bounds check. This could lead to a remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70637599.
nvd
CVE-2021-39706P3HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39706 [HIGH] CWE-862 CVE-2021-39706: In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials sto In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-
nvd
CVE-2020-0099P3HIGHCVSS 7.8v8.0v8.1+3 more2020-12-14
CVE-2020-0099 [HIGH] CWE-1188 CVE-2020-0099: In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insec In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android I
nvd
CVE-2021-0305P3HIGHCVSS 7.8v8.1v9.0+2 more2021-02-10
CVE-2021-0305 [HIGH] CWE-1021 CVE-2021-0305: In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This co In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-154015447
nvd
CVE-2020-27045P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27045 [HIGH] CWE-787 CVE-2020-27045: In CE_SendRawFrame of ce_main.cc, there is a possible out of bounds write due to a heap buffer overf In CE_SendRawFrame of ce_main.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649398
nvd
Google Android vulnerabilities | cvebase