cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 102 of 339
CVE-2020-0210P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0210 [HIGH] CWE-610 CVE-2020-0210: In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a con In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206763
nvd
CVE-2019-2193P3HIGHCVSS 7.8v8.0v8.1+3 more2019-11-13
CVE-2019-2193 [HIGH] CWE-269 CVE-2019-2193: In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privilege, leaving an Admin app installed with no indication to the user, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers
nvd
CVE-2019-2127P3HIGHCVSS 7.8v7.0v7.1.1+5 more2019-08-20
CVE-2019-2127 [HIGH] CWE-416 CVE-2019-2127: In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corru In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.
nvd
CVE-2019-2096P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2096 [HIGH] CWE-415 CVE-2019-2096: In EffectRelease of EffectBundle.cpp, there is a possible memory corruption due to a double free. Th In EffectRelease of EffectBundle.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1
nvd
CVE-2021-0337P3HIGHCVSS 7.8v8.1v9.0+3 more2021-02-10
CVE-2021-0337 [HIGH] CWE-312 CVE-2021-0337: In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metad In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-157474195
nvd
CVE-2020-0388P3HIGHCVSS 7.8v10.0v11.0+1 more2020-09-17
CVE-2020-0388 [HIGH] CWE-276 CVE-2020-0388: In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permis In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-156123
nvd
CVE-2018-9547P3HIGHCVSS 7.8v8.1v9.02018-12-06
CVE-2018-9547 [HIGH] CWE-20 CVE-2018-9547: In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-114223584.
nvd
CVE-2021-25461P3HIGHCVSS 7.8v8.12021-09-09
CVE-2021-25461 [HIGH] CWE-120 CVE-2021-25461: An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
nvd
CVE-2019-2221P3HIGHCVSS 7.8v10.0vAndroid-102019-12-06
CVE-2019-2221 [HIGH] CVE-2019-2221: In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user intera In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Androi
nvd
CVE-2019-9468P3HIGHCVSS 7.8fixed in 10.0vAndroid-102020-01-06
CVE-2019-9468 [HIGH] CWE-415 CVE-2019-9468: In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-139683471
nvd
CVE-2020-0375P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0375 [HIGH] CWE-862 CVE-2020-0375: In Telephony, there is a possible permission bypass due to a missing permission check. This could le In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253476
nvd
CVE-2020-0374P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0374 [HIGH] CWE-276 CVE-2020-0374: In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to loc In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156251602
nvd
CVE-2020-0266P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0266 [HIGH] CWE-862 CVE-2020-0266: In factory reset protection, there is a possible FRP bypass due to a missing permission check. This In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-111086459
nvd
CVE-2019-9429P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9429 [HIGH] CWE-787 CVE-2019-9429: In profman, there is a possible out of bounds write due to memory corruption. This could lead to loc In profman, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110035108
nvd
CVE-2019-2032P3HIGHCVSS 7.8v8.0v8.1+1 more2019-04-19
CVE-2019-2032 [HIGH] CWE-787 CVE-2019-2032: In SetScanResponseData of ble_advertiser_hci_interface.cc, there is a possible out-of-bound write du In SetScanResponseData of ble_advertiser_hci_interface.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-121
nvd
CVE-2018-9526P3HIGHCVSS 7.5v9.02018-11-14
CVE-2018-9526 [HIGH] CWE-200 CVE-2018-9526: In device configuration data, there is an improperly configured setting. This could lead to remote d In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112159033
nvd
CVE-2020-0233P3HIGHCVSS 7.8v10.0vAndroid kernel2020-06-11
CVE-2020-0233 [HIGH] CWE-416 CVE-2020-0233: In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150225255
nvd
CVE-2020-0078P3HIGHCVSS 7.8v9.0v10.0+1 more2020-04-17
CVE-2020-0078 [HIGH] CWE-787 CVE-2020-0078: In releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a missing bou In releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144766455
nvd
CVE-2019-9257P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9257 [HIGH] CWE-190 CVE-2019-9257: In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113572342
nvd
CVE-2019-2218P3HIGHCVSS 7.8v10.0vAndroid-8.0+3 more2019-12-06
CVE-2019-2218 [HIGH] CWE-862 CVE-2019-2218: In createSessionInternal of PackageInstallerService.java, there is a possible improper permission gr In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installing malicious packages with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Androi
nvd
Google Android vulnerabilities | cvebase