Android (associated with Google Inc. or Open Handset Alliance)

First CVE: Oct 1, 2015Active for: 11 years
5,140
CVEs Published
More CVEs Published than 97% of tracked CNAs
428.3
Avg CVEs / Year
More Avg CVEs / Year than 97% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked CNAs
0.3%
In CISA KEV
Higher KEV Rate than 81% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by Android (associated with Google Inc. or Open Handset Alliance) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2015
10 years ago
Most Recent CVE
Jun 18, 2026
37 days ago

Top CVEs

All CVEs published by Android (associated with Google Inc. or Open Handset Alliance) as a CNA, regardless of affected vendor or product.

5,140 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.892YESYES
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execut
Oct 1, 201510.086NOYES
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution p
Jun 1, 20268.481YESNO
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attacke
Oct 1, 201510.076NONO
Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code
Oct 1, 201510.075NONO
The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing
Oct 1, 201510.072NONO
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege wi
Sep 4, 20258.871YESNO
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additi
Dec 8, 20257.870YESNO
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship between chunk sizes and skip sizes
Oct 1, 20159.369NONO
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no
Sep 11, 20237.865YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA5,140 CVEs
Severity distribution among all CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local3,838 (74.7%)
Network1,025 (19.9%)
Unknown82 (1.6%)
Physical52 (1.0%)
Adjacent Network143 (2.8%)
Attack Complexity
Low4,705 (91.5%)
High353 (6.9%)
Unknown82 (1.6%)
User Interaction
None3,382 (65.8%)
Unknown82 (1.6%)
Required1,676 (32.6%)
Privileges Required
Low2,031 (39.5%)
High556 (10.8%)
None2,471 (48.1%)
Unknown82 (1.6%)

Exploit Exposure

Signals from CVEs in this cna scope (5140 CVEs).

CISA KEV
14 CVEs
0.3% of CVEs· 81st percentile
Metasploit
3 CVEs
0.1% of CVEs· 77th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
37 CVEs
0.7% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Android (associated with Google Inc. or Open Handset Alliance) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Android (associated with Google Inc. or Open Handset Alliance) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs