cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 117 of 339
CVE-2020-0150P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0150 [HIGH] CWE-787 CVE-2020-0150: In rw_t3t_message_set_block_list of rw_t3t.cc, there is a possible out of bounds write due to a miss In rw_t3t_message_set_block_list of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142280329
nvd
CVE-2019-2026P3HIGHCVSS 7.8v8.02019-04-19
CVE-2019-2026 [HIGH] CWE-862 CVE-2019-2026: In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a m In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local escalation of privilege and FRP bypass with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0Android ID: A-120866126
nvd
CVE-2019-9295P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9295 [HIGH] CWE-862 CVE-2019-9295: In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missin In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-36885811
nvd
CVE-2020-0298P3HIGHCVSS 7.8v11.0vAndroid-112020-09-18
CVE-2020-0298 [HIGH] CWE-862 CVE-2020-0298: In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission c In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145129266
nvd
CVE-2018-9425P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2018-9425 [HIGH] CWE-269 CVE-2018-9425: In Platform, there is a possible bypass of user interaction requirements due to missing permission c In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73884967
nvd
CVE-2019-9263P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9263 [HIGH] CWE-862 CVE-2019-9263: In telephony, there is a possible bypass of user interaction requirements due to missing permission In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73136824
nvd
CVE-2021-0369P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0369 [HIGH] CVE-2021-0369: In CrossProfileAppsServiceImpl.java, there is the possibility of an application's INTERACT_ACROSS_PR In CrossProfileAppsServiceImpl.java, there is the possibility of an application's INTERACT_ACROSS_PROFILES grant state not displaying properly in the setting UI due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: A
nvd
CVE-2020-0089P3HIGHCVSS 7.8v11.0vAndroid-112020-09-18
CVE-2020-0089 [HIGH] CWE-862 CVE-2020-0089: In the audio server, there is a missing permission check. This could lead to local escalation of pri In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137015603
nvd
CVE-2020-0109P3HIGHCVSS 7.8v9.0v10.0+1 more2020-05-14
CVE-2020-0109 [HIGH] CWE-862 CVE-2020-0109: In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission check. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-1480
nvd
CVE-2020-35555P3HIGHCVSS 7.8v10.02020-12-18
CVE-2020-35555 [HIGH] CVE-2020-35555: An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configu An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported, the device does not lock upon disconnection of a call with the cover closed. The LG ID is LVE-SMP-200027 (December 2020).
nvd
CVE-2021-25408P3HIGHCVSS 7.8v9.0v10.0+1 more2021-06-11
CVE-2021-25408 [HIGH] CWE-787 CVE-2021-25408: A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitr A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2022-22292P3HIGHCVSS 7.8v10.0v11.0+1 more2022-02-11
CVE-2022-22292 [HIGH] CWE-280 CVE-2022-22292: Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted application Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.
nvd
CVE-2023-20953P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-20953 [HIGH] CVE-2023-20953: In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to bypass factory reset p In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to bypass factory reset protection due to incorrect UI being shown prior to setup completion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-2
nvd
CVE-2022-20218P3HIGHCVSS 7.8v12.0v12.1+1 more2022-07-13
CVE-2022-20218 [HIGH] CWE-732 CVE-2022-20218: In PermissionController, there is a possible way to get and retain permissions without user's consen In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-223907044
nvd
CVE-2021-0593P3HIGHCVSS 7.8v8.1v9.0+3 more2021-08-17
CVE-2021-0593 [HIGH] CWE-610 CVE-2021-0593: In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileg In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileged broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9An
nvd
CVE-2021-25517P3HIGHCVSS 7.8v10.0v11.02021-12-08
CVE-2021-25517 [HIGH] CWE-20 CVE-2021-25517: An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.
nvd
CVE-2023-32847P3HIGHCVSS 7.8v12.0v13.02023-12-04
CVE-2023-32847 [HIGH] CWE-787 CVE-2023-32847: In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08241940; Issue ID: ALPS08241940.
nvd
CVE-2023-32851P3HIGHCVSS 7.8v11.0v12.02023-12-04
CVE-2023-32851 [HIGH] CWE-787 CVE-2023-32851: In decoder, there is a possible out of bounds write due to a missing bounds check. This could lead t In decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08016652; Issue ID: ALPS08016652.
nvd
CVE-2022-39854P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-07
CVE-2022-39854 [HIGH] CWE-284 CVE-2022-39854: Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure me Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.
nvd
CVE-2019-1997P3HIGHCVSS 7.5v7.0v7.1.1+4 more2019-02-28
CVE-2019-1997 [HIGH] CWE-330 CVE-2019-1997: In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure de In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure default value. This could lead to local information disclosure via an insecure wireless connection with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-
nvd
Google Android vulnerabilities | cvebase