Vulnerability index

Browse CVEs

4,652 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Android MEDIUM 5.7
CVE-2026-0165

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote info…

Mitigation only
Fix from $1,600 2026-06-16
Android HIGH 8.8
CVE-2026-0146

In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This could lead to…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 8.8
CVE-2026-0147

In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could l…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 8.8
CVE-2026-0148

In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remot…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 8.8
CVE-2026-0149

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no addit…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 8.8
CVE-2026-0151

In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with …

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0143

In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0150

In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to local esc…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0152

In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of bounds due to …

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0153

In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2026-06-16
Android MEDIUM 6.5
CVE-2026-0144

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of s…

Mitigation only
Fix from $1,600 2026-06-16
Android HIGH 8.8
CVE-2026-0132

In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional executio…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 8.8
CVE-2026-0139

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional executio…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0133

In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check.…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0135

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional execution…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0137

In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to lo…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.8
CVE-2026-0138

In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2026-06-16
Android MEDIUM 6.5
CVE-2026-0136

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,600 2026-06-16
Android CRITICAL 9.8
CVE-2026-0126

In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execu…

Mitigation only
Fix from $2,300 2026-06-16
Android HIGH 7.3
CVE-2026-0131

In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2026-06-16
Android HIGH 7.0
CVE-2026-0125

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wi…

Mitigation only
Fix from $1,950 2026-06-16
Android MEDIUM 6.5
CVE-2026-0127

In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead …

No fix yet
Fix from $1,600 2026-06-16
Android MEDIUM 6.5
CVE-2026-0128

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclos…

Mitigation only
Fix from $1,600 2026-06-16
Android HIGH 7.8
CVE-2026-28580

In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege w…

No fix yet
Fix from $1,950 2026-06-01
Android HIGH 7.8
CVE-2026-28577

In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalati…

Mitigation only
Fix from $1,950 2026-06-01
Android MEDIUM 5.5
CVE-2026-28578

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could le…

Mitigation only
Fix from $1,600 2026-06-01
Android HIGH 8.0
CVE-2026-0095

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an i…

Mitigation only
Fix from $1,950 2026-06-01
Android HIGH 8.0
CVE-2026-0097

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (…

Mitigation only
Fix from $1,950 2026-06-01
Android HIGH 7.8
CVE-2026-0096

In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. …

Mitigation only
Fix from $1,950 2026-06-01
Android HIGH 7.8
CVE-2026-0098

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to l…

Mitigation only
Fix from $1,950 2026-06-01