VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2023-21391
In Messaging, there is a possible way to disable the messaging application due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-30 · Modified
7.5EPSS 0.004
CVE-2020-0228
There is an improper configuration of recorder related service. Product: AndroidVersions: Android SoCAndroid ID: A-156333723
Published 2020-07-17 · Modified
7.5EPSS 0.004
CVE-2023-48403
In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure if the attacker is able to observe the behavior of the subsequent switch conditional with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-08 · Modified
7.5EPSS 0.004
CVE-2018-5820
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the function wma_tbttoffset_update_event_handler(), a parameter received from firmware is used to allocate memory for a local buffer and is not properly validated. This can potentially result in an integer overflow subsequently leading to a heap overwrite.
Published 2018-04-03 · Modified
7.5EPSS 0.004
CVE-2018-5822
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, compromised WLAN FW can potentially cause a buffer overwrite.
Published 2018-04-03 · Modified
7.5EPSS 0.004
CVE-2017-11031
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the VIDIOC_G_SDE_ROTATOR_FENCE ioctl command can be used to cause a Use After Free condition.
Published 2017-12-05 · Modified
7.5EPSS 0.004
CVE-2017-11058
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.
Published 2017-11-16 · Modified
7.5EPSS 0.004
CVE-2017-11066
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing ubi image an uninitialized memory could be accessed.
Published 2018-01-10 · Modified
7.5EPSS 0.004
CVE-2017-11090
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in __wlan_hdd_cfg80211_set_pmksa when user space application sends PMKID of size less than WLAN_PMKID_LEN bytes.
Published 2017-11-16 · Modified
7.5EPSS 0.004
CVE-2017-11093
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer Over-read in Display due to the lack of an upper-bound validation when reading "num_of_cea_blocks" from the untrusted source (EDID), kernel memory can be exposed.
Published 2017-11-16 · Modified
7.5EPSS 0.004
CVE-2017-13169
An information disclosure vulnerability in the kernel camera server. Product: Android. Versions: Android kernel. Android ID A-37512375.
Published 2017-12-06 · Modified
7.5EPSS 0.004
CVE-2017-13175
An information disclosure vulnerability in the NVIDIA libwilhelm. Product: Android. Versions: Android kernel. Android ID A-64339309. References: N-CVE-2017-13175.
Published 2017-12-06 · Modified
7.5EPSS 0.004
CVE-2017-14870
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating the recovery message for eMMC devices, 1088 bytes of stack memory can potentially be leaked.
Published 2018-01-10 · Modified
7.5EPSS 0.004
CVE-2017-6275
An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from an arbitrary kernel address. This issue is rated as moderate. Product: Pixel. Versions: N/A. Android ID: A-34702397. References: N-CVE-2017-6275.
Published 2017-11-14 · Modified
7.5EPSS 0.004
CVE-2017-9696
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer over-read is possible in camera driver function msm_isp_stop_stats_stream. Variable stream_cfg_cmd->num_streams is from userspace, and it is not checked against "MSM_ISP_STATS_MAX".
Published 2017-11-16 · Modified
7.5EPSS 0.004
CVE-2017-9701
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing OEM unlock/unlock-go fastboot commands data leak may occur, resulting from writing uninitialized stack structure to non-volatile memory.
Published 2017-11-16 · Modified
7.5EPSS 0.004
CVE-2021-39646
Product: AndroidVersions: Android kernelAndroid ID: A-201537251References: N/A
Published 2021-12-15 · Modified
7.5EPSS 0.004
CVE-2023-48404
In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-08 · Modified
7.5EPSS 0.004
CVE-2023-48410
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-08 · Modified
7.5EPSS 0.004
CVE-2023-21339
In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-30 · Modified
7.5EPSS 0.004
CVE-2019-9275
In the Android kernel in the mnh driver there is a use after free due to improper locking. This could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2019-09-06 · Modified
7.5EPSS 0.004
CVE-2022-20188
Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2022-20184
Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2022-20177
Product: AndroidVersions: Android kernelAndroid ID: A-209906686References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2022-20175
Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2021-39716
Product: AndroidVersions: Android kernelAndroid ID: A-206977562References: N/A
Published 2022-03-16 · Modified
7.5EPSS 0.004
CVE-2022-20179
Product: AndroidVersions: Android kernelAndroid ID: A-211683760References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2022-20149
Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2022-20169
Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2022-20151
Product: AndroidVersions: Android kernelAndroid ID: A-210712565References: N/A
Published 2022-06-15 · Modified
7.5EPSS 0.004
CVE-2024-27229
In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-03-11 · Modified
7.5EPSS 0.004
CVE-2024-44101
there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-10-25 · Analyzed
7.5EPSS 0.004
CVE-2026-14064
Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-30 · Analyzed
7.5EPSS 0.004
CVE-2023-35661
In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-21347
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-30 · Modified
7.5EPSS 0.004
CVE-2026-55306
In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
7.5EPSS 0.004
CVE-2024-32894
In bc_get_converted_received_bearer of bc_utilities.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-06-13 · Modified
7.5EPSS 0.003
CVE-2017-13306
A elevation of privilege vulnerability in the Upstream kernel mnh driver. Product: Android. Versions: Android kernel. Android ID: A-70295063.
Published 2018-04-04 · Modified
7.5EPSS 0.003
CVE-2024-22011
In ss_ProcessRejectComponent of ss_MmConManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-03-11 · Modified
7.5EPSS 0.003
CVE-2024-29781
In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-06-13 · Modified
7.5EPSS 0.003
← Prev58 / 93Next →