VendorsGoogleandroidall versions
Vulnerabilities

Google Android

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9581CVEs
CVE-2014-9956
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36389611.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2014-9957
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36387564.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2014-9958
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384774.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2014-9959
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36383694.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2016-10298
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393252.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2020-12746
An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) (Exynos chipsets) software. Attackers can bypass the Secure Bootloader protection mechanism via a heap-based buffer overflow to execute arbitrary code. The Samsung ID is SVE-2020-16712 (May 2020).
Published 2020-05-11 · Modified
10.0EPSS 0.011
CVE-2017-14906
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.
Published 2018-03-30 · Modified
10.0EPSS 0.011
CVE-2016-8484
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823575.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2016-8488
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2016-8487
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823724.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2016-10233
An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34389926. References: QC-CR#897452.
Published 2018-04-04 · Modified
10.0EPSS 0.011
CVE-2016-2416
libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for the android.permission.DUMP permission, which allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via a dump request, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27046057.
Published 2016-04-18 · Modified
10.0EPSS 0.011
CVE-2015-9066
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an Inter-RAT procedure.
Published 2017-08-18 · Modified
10.0EPSS 0.011
CVE-2014-9976
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.
Published 2017-08-18 · Modified
10.0EPSS 0.011
CVE-2015-9063
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a procedure involving a remote UIM client.
Published 2017-08-18 · Modified
10.0EPSS 0.011
CVE-2016-10381
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2016-10380
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2015-9065
In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access Stratum security is established.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2015-0574
In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2016-10384
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a WLAN driver ioctl.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2016-10390
In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive amount of memory may be consumed.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2014-9971
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2014-9972
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2014-9981
In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient during boot.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2016-10392
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2016-10386
In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2016-10387
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.
Published 2017-08-18 · Modified
10.0EPSS 0.010
CVE-2016-5871
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow vulnerability exists when loading an image file.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2015-9062
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow vulnerability exists when loading an ELF file.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2015-9064
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request before NAS security has been activated.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2016-10385
In all Qualcomm products with Android releases from CAF using the Linux kernel, a use-after-free vulnerability exists in IMS RCS.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2019-2007
In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-120789744
Published 2019-06-19 · Modified
10.0EPSS 0.009
CVE-2016-2496
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.
Published 2016-06-13 · Modified
10.0EPSS 0.009
CVE-2015-9053
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the processing of certain responses from the USIM.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2015-9041
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists when performing WCDMA radio tuning.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2015-9034
In all Qualcomm products with Android releases from CAF using the Linux kernel, a string can fail to be null-terminated in SIP leading to a buffer overflow.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2014-9968
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the UIMDIAG interface.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2014-9977
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in PlayReady DRM.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2014-9978
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE service.
Published 2017-08-18 · Modified
10.0EPSS 0.009
CVE-2015-9042
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists when processing a QMI message.
Published 2017-08-18 · Modified
10.0EPSS 0.009
← Prev12 / 240Next →