Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android
Total 9324 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-27237 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27236 1 Google 1 Android 2026-06-17 N/A 8.4 HIGH
In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27235 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27234 1 Google 1 Android 2026-06-17 N/A 5.9 MEDIUM
In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27233 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27232 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27231 1 Google 1 Android 2026-06-17 N/A 5.9 MEDIUM
In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27230 1 Google 1 Android 2026-06-17 N/A 5.1 MEDIUM
In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
CVE-2024-27229 1 Google 1 Android 2026-06-17 N/A 7.5 HIGH
In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27228 1 Google 1 Android 2026-06-17 N/A 9.8 CRITICAL
there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27227 1 Google 1 Android 2026-06-17 N/A 9.8 CRITICAL
A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues
CVE-2024-27226 1 Google 1 Android 2026-06-17 N/A 8.4 HIGH
In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27225 1 Google 1 Android 2026-06-17 N/A 4.4 MEDIUM
In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27224 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27223 1 Google 1 Android 2026-06-17 N/A 5.1 MEDIUM
In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure after authenticating the cell connection with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27222 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27221 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27220 1 Google 1 Android 2026-06-17 N/A 8.4 HIGH
In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27219 1 Google 1 Android 2026-06-17 N/A 8.4 HIGH
In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-27218 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.