cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 105 of 339
CVE-2021-39707P3HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39707 [HIGH] CWE-610 CVE-2021-39707: In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A
nvd
CVE-2022-20488P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20488 [HIGH] CWE-1284 CVE-2022-20488: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-
nvd
CVE-2022-20485P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20485 [HIGH] CWE-770 CVE-2022-20485: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2022-20486P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20486 [HIGH] CWE-770 CVE-2022-20486: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2022-20487P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20487 [HIGH] CWE-770 CVE-2022-20487: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2021-39620P3HIGHCVSS 7.8v11.0v12.0+1 more2022-01-14
CVE-2021-39620 [HIGH] CWE-416 CVE-2021-39620: In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after f In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-203847542
nvd
CVE-2021-0445P3HIGHCVSS 7.8v9.0v11.0+1 more2021-04-13
CVE-2021-0445 [HIGH] CVE-2021-0445: In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. Thi In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9Android ID: A-172322502
nvd
CVE-2022-20461P3HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20461 [HIGH] CWE-843 CVE-2022-20461: In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege of BLE with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-
nvd
CVE-2021-0548P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0548 [HIGH] CWE-787 CVE-2021-0548: In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bound In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650357
nvd
CVE-2021-0536P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0536 [HIGH] CWE-610 CVE-2021-0536: In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a co In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176756691
nvd
CVE-2021-0534P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0534 [HIGH] CWE-1188 CVE-2021-0534: In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protec In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170639543
nvd
CVE-2021-1040P3HIGHCVSS 7.8v9.0v10.0+3 more2021-12-15
CVE-2021-1040 [HIGH] CWE-1021 CVE-2021-1040: In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/o In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182810085
nvd
CVE-2021-0611P3HIGHCVSS 7.8v10.0v11.02021-09-27
CVE-2021-0611 [HIGH] CWE-416 CVE-2021-0611: In m4u, there is a possible memory corruption due to a use after free. This could lead to local esca In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05425810.
nvd
CVE-2021-0612P3HIGHCVSS 7.8v10.0v11.02021-09-27
CVE-2021-0612 [HIGH] CWE-416 CVE-2021-0612: In m4u, there is a possible memory corruption due to a use after free. This could lead to local esca In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05425834.
nvd
CVE-2021-0372P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0372 [HIGH] CWE-732 CVE-2021-0372: In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174047735
nvd
CVE-2021-0376P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0376 [HIGH] CWE-863 CVE-2021-0376: In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-115619667
nvd
CVE-2021-0505P3HIGHCVSS 7.8v11.0vAndroid-112021-06-21
CVE-2021-0505 [HIGH] CWE-862 CVE-2021-0505: In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179975048
nvd
CVE-2021-0389P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0389 [HIGH] CWE-862 CVE-2021-0389: In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This cou In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168039904
nvd
CVE-2023-32850P3HIGHCVSS 7.8v11.0v12.02023-12-04
CVE-2023-32850 [HIGH] CWE-787 CVE-2023-32850: In decoder, there is a possible out of bounds write due to an integer overflow. This could lead to l In decoder, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08016659; Issue ID: ALPS08016659.
nvd
CVE-2022-20134P3HIGHCVSS 7.8v10.0v11.0+3 more2022-06-15
CVE-2022-20134 [HIGH] CWE-20 CVE-2022-20134: In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wr In readArguments of CallSubjectDialog.java, there is a possible way to trick the user to call the wrong phone number due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12
nvd
Google Android vulnerabilities | cvebase