VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2017-14872
While flashing a meta image, a buffer over-read can potentially occur when the number of images are out of the maximum range of 32 in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.
Published 2018-07-06 · Modified
5.5EPSS 0.002
CVE-2017-14893
While flashing meta image, a buffer over-read may potentially occur when the image size is smaller than the image header size or is smaller than the image header size + total image header entry in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.
Published 2018-07-06 · Modified
5.5EPSS 0.002
CVE-2018-5895
Buffer over-read may happen in wma_process_utf_event() due to improper buffer length validation before writing into param_buf->num_wow_packet_buffer in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.
Published 2018-07-06 · Modified
5.5EPSS 0.002
CVE-2022-20437
In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242258929
Published 2022-10-11 · Modified
5.5EPSS 0.002
CVE-2018-3579
In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, event->num_entries_in_page is a value received from firmware that is not properly validated which can lead to a buffer over-read
Published 2018-06-12 · Modified
5.5EPSS 0.002
CVE-2021-0938
In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-171418586References: Upstream kernel
Published 2021-10-25 · Modified
5.5EPSS 0.002
CVE-2017-15824
In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, the function UpdateDeviceStatus() writes a local stack buffer without initialization to flash memory using WriteToPartition() which may potentially leak memory.
Published 2018-07-06 · Modified
5.5EPSS 0.002
CVE-2017-6283
NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.
Published 2018-03-06 · Modified
5.5EPSS 0.002
CVE-2016-6708
An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypass of user interaction requirements for any developer or security setting modifications. Android ID: A-30693465.
Published 2016-11-25 · Modified
5.5EPSS 0.002
CVE-2017-18169
User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
Published 2018-06-15 · Modified
5.5EPSS 0.001
CVE-2021-39800
In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-208277166References: Upstream kernel
Published 2022-04-12 · Modified
5.5EPSS 0.001
CVE-2016-3853
Google Play services in Android before 2016-08-05 on Nexus devices allow local users to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26803208.
Published 2016-08-05 · Modified
5.5EPSS 0.001
CVE-2021-0463
In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154867068
Published 2021-03-10 · Modified
5.5EPSS 0.001
CVE-2026-13929
Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
5.5EPSS 0.001
CVE-2022-20227
In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216825460References: Upstream kernel
Published 2022-07-13 · Modified
5.5EPSS 0.001
CVE-2018-12006
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potentially access leaked data due to uninitialized padding present in display function.
Published 2019-02-11 · Modified
5.5EPSS 0.001
CVE-2018-12011
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.
Published 2019-02-11 · Modified
5.5EPSS 0.001
CVE-2019-9472
In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-130237611
Published 2020-01-06 · Modified
5.5EPSS 0.001
CVE-2017-17769
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.
Published 2018-03-30 · Modified
5.5EPSS 0.001
CVE-2020-0090
An improper authorization in the receiver component of Email.Product: AndroidVersions: Android SoCAndroid ID: A-149813048
Published 2020-05-14 · Modified
5.5EPSS 0.001
CVE-2020-0091
In mnld, an incorrect configuration in driver_cfg of mnld for meta factory mode.Product: AndroidVersions: Android SoCAndroid ID: A-149808700
Published 2020-05-14 · Modified
5.5EPSS 0.001
CVE-2023-40101
In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-30 · Modified
5.5EPSS 0.001
CVE-2020-0064
An improper authorization while processing the provisioning data.Product: AndroidVersions: Android SoCAndroid ID: A-149866855
Published 2020-05-14 · Modified
5.5EPSS 0.001
CVE-2020-0065
An improper authorization in the receiver component of the Android Suite Daemon.Product: AndroidVersions: Android SoCAndroid ID: A-149813448
Published 2020-05-14 · Modified
5.5EPSS 0.001
CVE-2022-42528
In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-242203672References: N/A
Published 2023-03-24 · Modified
5.5EPSS 0.001
CVE-2018-5860
In the MDSS driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, a data structure may be used without being initialized correctly.
Published 2018-06-15 · Modified
5.5EPSS 0.001
CVE-2022-20531
In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-30 · Modified
5.5EPSS 0.001
CVE-2017-6288
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-65482562. Reference: N-CVE-2017-6288.
Published 2018-03-12 · Modified
5.5EPSS 0.001
CVE-2017-6285
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-64893156. Reference: N-CVE-2017-6285.
Published 2018-03-12 · Modified
5.5EPSS 0.001
CVE-2017-6287
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate.Product: Android. Version: N/A. Android: A-64893264. Reference: N-CVE-2017-6287.
Published 2018-03-12 · Modified
5.5EPSS 0.001
CVE-2023-44126
Call management - Implicit intents disclose telephony data such as phone numbers, call states, contacts
Published 2023-09-27 · Modified
5.5EPSS 0.001
CVE-2023-44127
Call management - Implicit activity intents disclose contact details and phone numbers
Published 2023-09-27 · Modified
5.5EPSS 0.001
CVE-2016-11035
An issue was discovered on Samsung mobile devices with software through 2016-05-27 (Exynos AP chipsets). A local graphics user can cause a Kernel Crash via the fb0(DECON) frame buffer interface. The Samsung ID is SVE-2016-7011 (October 2016).
Published 2020-04-07 · Modified
5.5EPSS 0.001
CVE-2022-20608
In Pixel cellular firmware, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239239246References: N/A
Published 2022-12-16 · Modified
5.5EPSS 0.001
CVE-2022-20609
In Pixel cellular firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239240808References: N/A
Published 2022-12-16 · Modified
5.5EPSS 0.001
CVE-2026-87552
Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)
Published 2026-09-09 · Modified
5.5EPSS 0.001
CVE-2021-0695
In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-184018316References: Upstream kernel
Published 2021-10-06 · Modified
5.5EPSS 0.001
CVE-2026-79146
Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Published 2026-08-25 · Analyzed
5.5EPSS 0.001
CVE-2020-13843
An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June 2020).
Published 2020-06-04 · Modified
5.5EPSS 0.001
CVE-2021-0639
In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-190724551
Published 2021-08-17 · Modified
5.5EPSS 0.001
← Prev78 / 93Next →