VendorsGoogleandroidall versions
Vulnerabilities

Google Android

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9581CVEs
CVE-2023-21066
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-250100597References: N/A
Published 2023-06-28 · Modified
9.8EPSS 0.005
CVE-2023-21287
In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
9.8EPSS 0.005
CVE-2018-21038
An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018).
Published 2020-04-08 · Modified
9.8EPSS 0.005
CVE-2017-0824
An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.
Published 2017-10-03 · Modified
9.8EPSS 0.005
CVE-2017-0829
An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.
Published 2017-10-03 · Modified
9.8EPSS 0.005
CVE-2017-0828
An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.
Published 2017-10-03 · Modified
9.8EPSS 0.005
CVE-2022-20386
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20391
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20390
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20387
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20389
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2022-20388
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
Published 2022-09-13 · Modified
9.8EPSS 0.005
CVE-2024-43091
In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-11-13 · Analyzed
9.8EPSS 0.005
CVE-2017-13274
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71360761.
Published 2018-04-04 · Modified
9.8EPSS 0.005
CVE-2023-21058
In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-246169606References: N/A
Published 2023-03-24 · Modified
9.8EPSS 0.005
CVE-2023-20954
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261867748
Published 2023-03-24 · Modified
9.8EPSS 0.005
CVE-2023-20951
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258652631
Published 2023-03-24 · Modified
9.8EPSS 0.005
CVE-2023-21057
In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-244450646References: N/A
Published 2023-03-24 · Modified
9.8EPSS 0.005
CVE-2022-20532
In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-232242894
Published 2023-03-24 · Modified
9.8EPSS 0.005
CVE-2023-20946
In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-244423101
Published 2023-02-28 · Modified
9.8EPSS 0.005
CVE-2020-0230
There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262
Published 2020-07-17 · Modified
9.8EPSS 0.005
CVE-2023-48423
In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-08 · Modified
9.8EPSS 0.005
CVE-2025-8042
Sandboxed iframe could start downloads
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2022-42537
Remote code execution
Published 2023-11-29 · Modified
9.8EPSS 0.005
CVE-2022-42536
Remote code execution
Published 2023-11-29 · Modified
9.8EPSS 0.005
CVE-2020-26607
An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingIntent with an empty intent is mishandled, allowing an attacker to perform a privileged action via a modified intent. The Samsung ID is SVE-2020-18418 (October 2020).
Published 2020-10-06 · Modified
9.8EPSS 0.005
CVE-2019-20563
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The SEC_FR trustlet has an out of bounds write. The Samsung ID is SVE-2019-15272 (October 2019).
Published 2020-03-24 · Modified
9.8EPSS 0.005
CVE-2019-20560
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The BIOSUB Trustlet has an out of bounds write. The Samsung ID is SVE-2019-15261 (October 2019).
Published 2020-03-24 · Modified
9.8EPSS 0.005
CVE-2018-3599
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while notifying a DCI client, a Use After Free condition can occur.
Published 2018-04-03 · Modified
9.8EPSS 0.005
CVE-2018-3596
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, legacy code vulnerable after migration has been removed.
Published 2018-04-03 · Modified
9.8EPSS 0.005
CVE-2023-21096
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-254774758
Published 2023-04-19 · Modified
9.8EPSS 0.005
CVE-2024-49747
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-01-21 · Analyzed
9.8EPSS 0.005
CVE-2020-0221
Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation could potentially return a pointer within the previous allocation's memory, which could lead to improper memory access.Product: AndroidVersions: Android kernelAndroid ID: A-135772851
Published 2020-05-14 · Modified
9.8EPSS 0.005
CVE-2020-25283
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September 2020).
Published 2020-09-11 · Modified
9.8EPSS 0.005
CVE-2026-55366
In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
9.8EPSS 0.005
CVE-2026-30783
RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
Published 2026-03-05 · Modified
9.8EPSS 0.005
CVE-2020-25062
An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020).
Published 2020-08-31 · Modified
9.8EPSS 0.005
CVE-2020-28340
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-18546 (November 2020).
Published 2020-11-08 · Modified
9.8EPSS 0.005
CVE-2019-20772
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Account subsystem allows authorization bypass. The LG ID is LVE-SMP-190007 (August 2019).
Published 2020-04-17 · Modified
9.8EPSS 0.005
CVE-2021-39655
Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A
Published 2021-12-15 · Modified
9.8EPSS 0.005
← Prev20 / 240Next →