← Back

Android

android

Vendor: Google • 8,153 CVEs

CVEs (8,153)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 6, 2026
Feb 7, 2016
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous reboo...Show more
Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.Show less
1Google
1Android
May 6, 2026
Feb 7, 2016
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug...Show more
The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug 25187394.Show less
1Google
1Android
May 6, 2026
Feb 7, 2016
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25344453.
1Google
1Android
May 6, 2026
Feb 7, 2016
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25...Show more
The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25773204.Show less
1Google
1Android
May 6, 2026
Feb 7, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 improperly manages mDrm...Show more
The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 improperly manages mDrmManagerClient objects, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25070434.Show less
1Google
1Android
May 6, 2026
Feb 7, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft...Show more
libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a large memory allocation in the (1) SoftMPEG4Encoder or (2) SoftVPXEncoder component, aka internal bug 25812794.Show less
2Apple
Google
5Android
Iphone OsMac Os X+2 more
May 6, 2026
Feb 7, 2016
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v...Show more
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.Show less
2Apple
Google
5Android
Iphone OsMac Os X+2 more
May 6, 2026
Feb 7, 2016
N/A· v4
9.8 CRITICAL· v3
8.3 HIGH· v2
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v...Show more
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.Show less
2Google
Mozilla
2Android
Firefox
May 6, 2026
Jan 31, 2016
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-serv...Show more
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.Show less
3Google
MozillaOpensuse
4Android
FirefoxLeap+1 more
May 6, 2026
Jan 31, 2016
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
2Google
Mozilla
2Android
Firefox
May 6, 2026
Jan 31, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
6.2 MEDIUM· v3
7.8 HIGH· v2
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource al...Show more
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager, aka internal bug 22300191, a different vulnerability than CVE-2015-7613.Show less
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
5.0 MEDIUM· v3
7.1 HIGH· v2
SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a crafted application, aka internal bug 23591205.
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
6.6 MEDIUM· v3
7.2 HIGH· v2
Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269...Show more
Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.Show less
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.8 HIGH· v2
The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by o...Show more
The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24157888.Show less
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
3.1 LOW· v3
2.9 LOW· v2
Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privi...Show more
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.Show less
1Google
1Android
May 6, 2026
Jan 6, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.