Vulnerabilities
Tracked app vulnerabilities
6,074 CVEs affect a tracked app or OS (all severities, Android). 47 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 6,074
- Actively exploited
- 47
- Publication window
- 2012-12-26 → 2026-08-04
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2016-2468
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2467
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2466
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2465
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2464
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2463
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2066
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2062
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2061
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-0718
HIGH 9.8
1 app
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers… |
|
CVE-2016-2457
MEDIUM 5.5
server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended res… |
|
CVE-2016-2446
HIGH 7.0
The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 2744135… |
|
CVE-2016-2842
CRITICAL 9.8
The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succee… |
|
CVE-2015-6384
N/A
1 app
The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended … |
|
CVE-2015-1283
LOW
1 app
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote … |
|
CVE-2015-1261
N/A
1 app
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL'… |
|
CVE-2015-1212
N/A
1 app
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to c… |
|
CVE-2015-1211
N/A
1 app
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows… |
|
CVE-2015-1210
N/A
1 app
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.22… |
|
CVE-2015-1209
N/A
1 app
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in … |
|
CVE-2014-7905
N/A
1 app
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows r… |
|
CVE-2014-3201
N/A
1 app
core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFR… |
|
CVE-2012-6140
N/A
2 apps
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local user… |
|
CVE-2012-5180
N/A
1 app
The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers … |