Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 104 of 339
CVE-2020-0405P3HIGHCVSS 7.8v11.0vAndroid-112020-09-18
CVE-2020-0405 [HIGH] CWE-281 CVE-2020-0405: In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingInt
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111
nvd
CVE-2020-0277P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0277 [HIGH] CWE-862 CVE-2020-0277: In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission c
In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a malicious app to modify the device's data plan with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID
nvd
CVE-2020-0341P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0341 [HIGH] CWE-862 CVE-2020-0341: In DisplayManager, there is a possible permission bypass due to a missing permission check. This cou
In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144920149
nvd
CVE-2019-2174P3HIGHCVSS 7.8v7.1.1v7.1.2+4 more2019-09-05
CVE-2019-2174 [HIGH] CWE-416 CVE-2019-2174: In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, t
In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0567P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0567 [HIGH] CWE-74 CVE-2021-0567: In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissio
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179461812
nvd
CVE-2020-0105P3HIGHCVSS 7.8v9.0v10.0+1 more2020-05-14
CVE-2020-0105 [HIGH] CWE-862 CVE-2020-0105: In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This c
In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This could lead to local escalation of privilege, allowing apps to use keyguard-bound keys when the screen is locked, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10A
nvd
CVE-2020-0083P3HIGHCVSS 7.5v10.0vAndroid-102020-03-10
CVE-2020-0083 [HIGH] CVE-2020-0083: In setRequirePmfInternal of sta_network.cpp, there is a possible default value being improperly appl
In setRequirePmfInternal of sta_network.cpp, there is a possible default value being improperly applied due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142797954
nvd
CVE-2019-2050P3HIGHCVSS 7.8v8.0v8.1+2 more2019-05-08
CVE-2019-2050 [HIGH] CWE-416 CVE-2019-2050: In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improp
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9 Android ID: A-121327323
nvd
CVE-2021-0477P3HIGHCVSS 7.8v8.1v9.0+3 more2021-06-11
CVE-2021-0477 [HIGH] CWE-732 CVE-2021-0477: In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission b
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID:
nvd
CVE-2020-0486P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0486 [HIGH] CWE-276 CVE-2020-0486: In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an
In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150857116
nvd
CVE-2020-27052P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27052 [HIGH] CWE-862 CVE-2020-27052: In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Loc
In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158833495
nvd
CVE-2024-0021P3HIGHCVSS 7.8v13.0v14.0+2 more2024-02-16
CVE-2024-0021 [HIGH] CWE-20 CVE-2024-0021: In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in th
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-39880P3HIGHCVSS 7.8v11.0v12.02022-11-09
CVE-2022-39880 [HIGH] CWE-20 CVE-2022-39880: Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows
Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.
nvd
CVE-2021-39627P3HIGHCVSS 7.8v9.0v10.0+3 more2022-01-14
CVE-2021-39627 [HIGH] CWE-732 CVE-2021-39627: In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions byp
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A
nvd
CVE-2021-39621P3HIGHCVSS 7.8v9.0v10.0+3 more2022-01-14
CVE-2021-39621 [HIGH] CWE-732 CVE-2021-39621: In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions byp
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A
nvd
CVE-2021-0684P3HIGHCVSS 7.8v8.1v9.0+3 more2021-10-06
CVE-2021-0684 [HIGH] CWE-416 CVE-2021-0684: In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a
In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-179839665
nvd
CVE-2021-0395P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0395 [HIGH] CWE-416 CVE-2021-0395: In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use afte
In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170315126
nvd
CVE-2023-20913P3HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2023-20913 [HIGH] CWE-1021 CVE-2023-20913: In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to misle
In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Androi
nvd
CVE-2021-0383P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0383 [HIGH] CVE-2021-0383: In done of CaptivePortalLoginActivity.java, there is a confused deputy. This could lead to local esc
In done of CaptivePortalLoginActivity.java, there is a confused deputy. This could lead to local escalation of privilege in carrier settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160871056
nvd
CVE-2021-39618P3HIGHCVSS 7.8v9.0v10.0+3 more2022-01-14
CVE-2021-39618 [HIGH] CVE-2021-39618: In multiple methods of EuiccNotificationManager.java, there is a possible way to install existing pa
In multiple methods of EuiccNotificationManager.java, there is a possible way to install existing packages without user consent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Androi
nvd