VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2012-4908
Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors involving a symlink.
Published 2012-09-13 · Modified
7.51 PoCEPSS 0.033
CVE-2018-15835
Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.
Published 2018-11-30 · Modified
7.5EPSS 0.020
CVE-2016-9065
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
Published 2018-06-11 · Modified
7.5EPSS 0.018
CVE-2021-34424
Process memory exposure in Zoom Client and other products
Published 2021-11-24 · Modified
7.5EPSS 0.017
CVE-2016-5299
A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
Published 2018-06-11 · Modified
7.5EPSS 0.016
CVE-2016-9061
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
Published 2018-06-11 · Modified
7.5EPSS 0.016
CVE-2014-8507
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a malformed WAPPush message, aka Bug 17969135.
Published 2014-12-15 · Modified
7.51 PoCEPSS 0.016
CVE-2020-6828
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient compromise such that it is generally equivalent to arbitrary code execution.<br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
Published 2020-04-24 · Modified
7.5EPSS 0.015
CVE-2016-1656
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.
Published 2016-04-18 · Modified
7.5EPSS 0.012
CVE-2023-33740
Incorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo the Verify parameter in a warning message.
Published 2023-05-30 · Modified
7.5EPSS 0.012
CVE-2018-5326
Cheetah Mobile CM Browser 5.22.06.0012, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.
Published 2018-01-12 · Modified
7.5EPSS 0.012
CVE-2018-5327
Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.
Published 2018-01-12 · Modified
7.5EPSS 0.012
CVE-2013-7373
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
Published 2014-04-29 · Modified
7.5EPSS 0.011
CVE-2014-1939
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.
Published 2014-03-03 · Modified
7.5EPSS 0.011
CVE-2020-5976
NVIDIA GeForce NOW, versions prior to 2.0.23 (Windows, macOS) and versions prior to 5.31 (Android, Shield TV), contains a vulnerability in the application software where the network test component transmits sensitive information insecurely, which may lead to information disclosure.
Published 2020-09-18 · Modified
7.5EPSS 0.011
CVE-2014-3164
cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers to cause a denial of service (NULL pointer dereference, or out-of-bounds write) via vectors related to binder passed lengths.
Published 2017-10-18 · Modified
7.5EPSS 0.010
CVE-2026-34711
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
Published 2026-06-09 · Analyzed
7.5EPSS 0.010
CVE-2017-11089
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in nl80211_set_station when user space application sends attribute NL80211_ATTR_LOCAL_MESH_POWER_MODE with data of size less than 4 bytes
Published 2017-11-16 · Modified
7.5EPSS 0.010
CVE-2026-48352
CAI Content Credentials | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
7.5EPSS 0.009
CVE-2026-48351
CAI Content Credentials | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
7.5EPSS 0.009
CVE-2015-1529
Integer overflow in soundtrigger/ISoundTriggerHwService.cpp in Android allows attacks to cause a denial of service via unspecified vectors.
Published 2017-05-23 · Modified
7.5EPSS 0.009
CVE-2014-3161
The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly interact with redirects, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that hosts a video stream.
Published 2014-07-20 · Modified
7.5EPSS 0.009
CVE-2022-42527
In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-244448906References: N/A
Published 2022-12-16 · Modified
7.5EPSS 0.009
CVE-2014-7919
b/libs/gui/ISurfaceComposer.cpp in Android allows attackers to trigger a denial of service (null pointer dereference and process crash).
Published 2017-06-08 · Modified
7.5EPSS 0.009
CVE-2018-3577
While processing fragments, when the fragment count becomes very large, an integer overflow leading to a buffer overflow can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.
Published 2018-07-06 · Modified
7.5EPSS 0.008
CVE-2026-48295
CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)
Published 2026-07-14 · Analyzed
7.5EPSS 0.008
CVE-2016-10235
A denial of service vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-34390620. References: QC-CR#1046409.
Published 2018-04-04 · Modified
7.5EPSS 0.008
CVE-2022-20605
In SAECOMM_CopyBufferBytes of SAECOMM_Utility.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-231722405References: N/A
Published 2022-12-16 · Modified
7.5EPSS 0.008
CVE-2022-42524
In sms_GetTpUdlIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-243401445References: N/A
Published 2022-12-16 · Modified
7.5EPSS 0.008
CVE-2023-33741
Macrovideo v380pro v1.4.97 shares the device id and password when sharing the device.
Published 2023-05-30 · Modified
7.5EPSS 0.008
CVE-2021-43189
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
Published 2021-11-09 · Modified
7.5EPSS 0.008
CVE-2021-39726
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-181782896References: N/A
Published 2022-03-16 · Modified
7.5EPSS 0.008
CVE-2016-8485
An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823681.
Published 2018-04-04 · Modified
7.5EPSS 0.007
CVE-2016-8486
An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823691.
Published 2018-04-04 · Modified
7.5EPSS 0.007
CVE-2023-22337
Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
Published 2023-11-14 · Modified
7.5EPSS 0.007
CVE-2023-39228
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
Published 2023-11-14 · Modified
7.5EPSS 0.007
CVE-2023-22285
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.
Published 2023-11-14 · Modified
7.5EPSS 0.007
CVE-2017-7759
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.
Published 2018-06-11 · Modified
7.5EPSS 0.007
CVE-2017-13222
An information disclosure vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-38159576.
Published 2018-01-12 · Modified
7.5EPSS 0.007
CVE-2020-0062
In Euicc, there is a possible information disclosure due to an included test Certificate. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143232031
Published 2020-03-10 · Modified
7.5EPSS 0.006
← Prev56 / 93Next →