VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2017-14877
While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL commands there is no mutex lock of allocated memory. If one thread sends an ioctl cmd IPA_IOC_QUERY_RT_TBL_INDEX while another sends an ioctl cmd IPA_IOC_DEL_RT_RULE, a use-after-free condition may occur.
Published 2018-03-30 · Modified
9.8EPSS 0.006
CVE-2017-14876
In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter params->entries[i].vfe_intf comes from userspace without any bounds check which could potentially result in a kernel out-of-bounds write.
Published 2018-03-30 · Modified
9.8EPSS 0.006
CVE-2017-14881
While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-13, a use-after-free condition may potentially occur.
Published 2018-03-30 · Modified
9.8EPSS 0.006
CVE-2020-0447
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168251617
Published 2020-11-10 · Modified
9.8EPSS 0.006
CVE-2022-42529
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A
Published 2022-12-16 · Modified
9.8EPSS 0.006
CVE-2020-0445
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264527
Published 2020-11-10 · Modified
9.8EPSS 0.005
CVE-2020-0446
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264528
Published 2020-11-10 · Modified
9.8EPSS 0.005
CVE-2026-16280
GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset
Published 2026-07-24 · Analyzed
9.8EPSS 0.005
CVE-2022-42541
Remote code execution
Published 2023-11-29 · Modified
9.8EPSS 0.005
CVE-2023-21066
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-250100597References: N/A
Published 2023-06-28 · Modified
9.8EPSS 0.005
CVE-2017-0828
An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.
Published 2017-10-03 · Modified
9.8EPSS 0.005
CVE-2017-0824
An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.
Published 2017-10-03 · Modified
9.8EPSS 0.005
CVE-2017-0829
An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.
Published 2017-10-03 · Modified
9.8EPSS 0.005
CVE-2022-20388
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20386
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20389
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20391
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20387
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20390
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2023-21058
In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-246169606References: N/A
Published 2023-03-24 · Modified
9.8EPSS 0.005
CVE-2023-21057
In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-244450646References: N/A
Published 2023-03-24 · Modified
9.8EPSS 0.005
CVE-2020-0230
There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262
Published 2020-07-17 · Modified
9.8EPSS 0.005
CVE-2023-48423
In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-08 · Modified
9.8EPSS 0.005
CVE-2025-8042
Sandboxed iframe could start downloads
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2022-42537
Remote code execution
Published 2023-11-29 · Modified
9.8EPSS 0.005
CVE-2022-42536
Remote code execution
Published 2023-11-29 · Modified
9.8EPSS 0.005
CVE-2018-3599
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while notifying a DCI client, a Use After Free condition can occur.
Published 2018-04-03 · Modified
9.8EPSS 0.005
CVE-2018-3596
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, legacy code vulnerable after migration has been removed.
Published 2018-04-03 · Modified
9.8EPSS 0.005
CVE-2020-0221
Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation could potentially return a pointer within the previous allocation's memory, which could lead to improper memory access.Product: AndroidVersions: Android kernelAndroid ID: A-135772851
Published 2020-05-14 · Modified
9.8EPSS 0.005
CVE-2026-55366
In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
9.8EPSS 0.005
CVE-2026-30783
RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
Published 2026-03-05 · Modified
9.8EPSS 0.005
CVE-2021-39641
Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A
Published 2021-12-15 · Modified
9.8EPSS 0.005
CVE-2021-39655
Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A
Published 2021-12-15 · Modified
9.8EPSS 0.005
CVE-2021-39644
Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A
Published 2021-12-15 · Modified
9.8EPSS 0.005
CVE-2017-6274
An elevation of Privilege vulnerability exists in the Thermal Driver, where a missing bounds checks in the thermal throttle driver can cause an out-of-bounds write in the kernel. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-34705801. References: N-CVE-2017-6274.
Published 2017-11-14 · Modified
9.8EPSS 0.005
CVE-2018-9580
A Elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-76222002.
Published 2018-11-14 · Modified
9.8EPSS 0.005
CVE-2020-0235
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "struct crus_sp_ioctl_header".Product: AndroidVersions: Android kernelAndroid ID: A-135129430
Published 2020-06-16 · Modified
9.8EPSS 0.004
CVE-2020-0223
This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450
Published 2020-06-16 · Modified
9.8EPSS 0.004
CVE-2020-0232
Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the session object and delete it using abc_pcie_dma_user_xfer_clean. If this happens, abc_pcie_start_dma_xfer and abc_pcie_wait_dma_xfer in the original thread will trigger UAF when working with the transfer object.Product: AndroidVersions: Android kernelAndroid ID: A-151453714
Published 2020-06-16 · Modified
9.8EPSS 0.004
CVE-2020-0231
There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156333727
Published 2020-07-17 · Modified
9.8EPSS 0.004
← Prev13 / 93Next →