cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 99 of 339
CVE-2020-27050P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27050 [HIGH] CWE-787 CVE-2020-27050: In rw_i93_send_cmd_write_multi_blocks of rw_i93.cc, there is a possible out of bounds write due to a In rw_i93_send_cmd_write_multi_blocks of rw_i93.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650365
nvd
CVE-2020-27051P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27051 [HIGH] CWE-190 CVE-2020-27051: In NFA_RwI93WriteMultipleBlocks of nfa_rw_api.cc, there is a possible out of bounds write due to an In NFA_RwI93WriteMultipleBlocks of nfa_rw_api.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650338
nvd
CVE-2020-0001P3HIGHCVSS 7.8v8.0v8.1+6 more2020-01-08
CVE-2020-0001 [HIGH] CVE-2020-0001: In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. Th In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-140055304
nvd
CVE-2021-39701P3HIGHCVSS 7.8v11.0v12.0+1 more2022-03-16
CVE-2021-39701 [HIGH] CWE-20 CVE-2021-39701: In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersi
nvd
CVE-2024-20027P3HIGHCVSS 7.9v12.0v13.0+1 more2024-03-04
CVE-2024-20027 [HIGH] CWE-787 CVE-2024-20027: In da, there is a possible out of bounds write due to improper input validation. This could lead to In da, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541633.
nvd
CVE-2018-9542P3HIGHCVSS 7.5v7.0v7.1.1+4 more2018-11-14
CVE-2018-9542 [HIGH] CWE-125 CVE-2018-9542: In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Andr
nvd
CVE-2018-9541P3HIGHCVSS 7.5v7.0v7.1.1+4 more2018-11-14
CVE-2018-9541 [HIGH] CWE-125 CVE-2018-9541: In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 And
nvd
CVE-2018-9540P3HIGHCVSS 7.5v7.0v7.1.1+4 more2018-11-14
CVE-2018-9540 [HIGH] CWE-125 CVE-2018-9540: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a possible out of bounds read due to a miss In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-
nvd
CVE-2018-9562P3HIGHCVSS 7.5v9.02018-12-06
CVE-2018-9562 [HIGH] CWE-125 CVE-2018-9562: In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parame In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113164621.
nvd
CVE-2017-13291P3HIGHCVSS 7.5v7.0v7.1.1+3 more2018-04-04
CVE-2017-13291 [HIGH] CWE-476 CVE-2017-13291: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible NULL pointer dereference due to In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible NULL pointer dereference due to missing bounds checks. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71603553.
nvd
CVE-2021-39794P3HIGHCVSS 7.8v11.0v12.0+2 more2022-04-12
CVE-2021-39794 [HIGH] CWE-276 CVE-2021-39794: In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell u In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 A
nvd
CVE-2017-13286P3HIGHCVSS 7.8v8.0v8.12018-04-04
CVE-2017-13286 [HIGH] CWE-502 CVE-2017-13286: In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android.
nvd
CVE-2019-2232P3HIGHCVSS 7.5v8.0v8.1+3 more2019-12-06
CVE-2019-2232 [HIGH] CWE-20 CVE-2019-2232: In handleRun of TextLine.java, there is a possible application crash due to improper input validatio In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-14063
nvd
CVE-2020-0188P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0188 [HIGH] CVE-2020-0188: In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass d In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147355897
nvd
CVE-2021-39771P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39771 [HIGH] CWE-20 CVE-2021-39771: In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to im In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-198661951
nvd
CVE-2021-0351P3HIGHCVSS 7.5v8.1v9.0+3 more2021-02-04
CVE-2021-0351 [HIGH] CVE-2021-0351: In wlan driver, there is a possible system crash due to a missing bounds check. This could lead to r In wlan driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11; Patch ID: ALPS05412917.
nvd
CVE-2016-5340P3HIGHCVSS 7.8≤ 7.02016-08-07
CVE-2016-5340 [HIGH] CWE-20 CVE-2016-5340: The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Cen The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.
nvd
CVE-2016-6691P3CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-6691 [CRITICAL] CWE-172 CVE-2016-6691: service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android befo service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.
nvd
CVE-2019-9423P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9423 [HIGH] CWE-787 CVE-2019-9423: In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds che In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616
nvd
CVE-2014-9914P3HIGHCVSS 7.8≤ 7.1.12017-02-07
CVE-2014-9914 [HIGH] CWE-362 CVE-2014-9914: Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel be Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
nvd
Google Android vulnerabilities | cvebase