VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2017-9709
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a privilege escalation vulnerability exists in telephony.
Published 2017-12-05 · Modified
9.8EPSS 0.004
CVE-2017-11079
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing sparse image, uninitialized heap memory can potentially be flashed due to the lack of validation of sparse image block header size.
Published 2018-01-10 · Modified
9.8EPSS 0.004
CVE-2017-15813
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overflow can occur while reading firmware logs.
Published 2017-12-05 · Modified
9.8EPSS 0.004
CVE-2016-11028
An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a stack-based buffer overflow in the OTP TrustZone trustlet. The Samsung IDs are SVE-2016-7173 and SVE-2016-7174 (December 2016).
Published 2020-04-07 · Modified
9.8EPSS 0.004
CVE-2016-11025
An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).
Published 2020-04-07 · Modified
9.8EPSS 0.004
CVE-2023-35646
In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
9.8EPSS 0.004
CVE-2023-35662
there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
9.8EPSS 0.004
CVE-2022-20385
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819
Published 2022-09-13 · Modified
9.8EPSS 0.004
CVE-2023-21162
In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21163
In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21402
In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21401
In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21218
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-35690
In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21217
In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21166
In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21228
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21403
In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21215
In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21164
In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2023-21263
In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2021-39815
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232440670
Published 2022-08-24 · Modified
9.8EPSS 0.004
CVE-2022-20122
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232441339
Published 2022-08-24 · Modified
9.8EPSS 0.004
CVE-2026-56960
In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
9.8EPSS 0.004
CVE-2023-21216
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2022-20403
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20402
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2026-0163
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-08-04 · Analyzed
9.8EPSS 0.004
CVE-2022-20365
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20378
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2021-0942
The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read. However, given that the OOB read value is ending up as the address field of a struct I think i seems plausible that this could lead to an OOB write if the attacker is able to cause the OOB read to pull an interesting kernel address. Regardless if this is a read or write, it is a High severity issue in the kernel.Product: AndroidVersions: Android SoCAndroid ID: A-238904312
Published 2022-09-13 · Modified
9.8EPSS 0.004
CVE-2022-20384
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20381
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20405
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2026-30793
RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
Published 2026-03-05 · Analyzed
9.8EPSS 0.003
CVE-2021-26277
Security Advisory | PendingIntent hijacking vulnerability in Framework Services
Published 2023-02-17 · Modified
9.8EPSS 0.003
CVE-2023-35647
In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
9.8EPSS 0.003
CVE-2023-35648
In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
9.8EPSS 0.003
CVE-2024-53842
In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-01-03 · Analyzed
9.8EPSS 0.003
CVE-2026-30789
RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
Published 2026-03-05 · Modified
9.8EPSS 0.003
← Prev14 / 93Next →