cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 124 of 339
CVE-2017-9686P3HIGHCVSS 7.8v8.02017-10-10
CVE-2017-9686 [HIGH] CWE-415 CVE-2017-9686: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possible double free/use after free in the SPS driver when debugfs logging is used.
nvd
CVE-2022-30754P3HIGHCVSS 7.8v10.0v11.0+1 more2022-07-12
CVE-2022-30754 [HIGH] CWE-20 CVE-2022-30754: Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows at Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.
nvd
CVE-2022-30756P3HIGHCVSS 7.8v10.0v11.0+1 more2022-07-12
CVE-2022-30756 [HIGH] CWE-20 CVE-2022-30756: Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attac Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.
nvd
CVE-2021-0438P3HIGHCVSS 7.8v8.1v9.0+2 more2021-04-13
CVE-2021-0438 [HIGH] CWE-1021 CVE-2021-0438: In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjacking attack due to an incorrect FLAG_OBSCURED value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Androi
nvd
CVE-2021-39668P3HIGHCVSS 7.8v11.0v12.0+1 more2022-02-11
CVE-2021-39668 [HIGH] CWE-610 CVE-2021-39668: In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused dep In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID:
nvd
CVE-2019-2090P3HIGHCVSS 7.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2090 [HIGH] CWE-862 CVE-2019-2090: In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypa In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing permissions check. This could lead to local escalation of privilege, with no additional permissions required. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-
nvd
CVE-2023-44123P3HIGHCVSS 7.8v12.0v13.02023-09-27
CVE-2023-44123 [HIGH] CWE-285 CVE-2023-44123: The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before mak
nvd
CVE-2023-44125P3HIGHCVSS 7.8v12.0v13.02023-09-27
CVE-2023-44125 [HIGH] CWE-285 CVE-2023-44125: The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before
nvd
CVE-2021-1017P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-1017 [HIGH] CWE-862 CVE-2021-1017: In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disa In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-1825
nvd
CVE-2022-39907P3HIGHCVSS 7.8v10.0v11.0+2 more2022-12-08
CVE-2022-39907 [HIGH] CWE-190 CVE-2022-39907: Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-202 Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.
nvd
CVE-2022-24928P3HIGHCVSS 7.8v11.02022-03-10
CVE-2022-24928 [HIGH] CWE-815 CVE-2022-24928: Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.
nvd
CVE-2021-39768P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39768 [HIGH] CWE-862 CVE-2021-39768: In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-202017876
nvd
CVE-2022-20212P3HIGHCVSS 7.8v10.0v11.0+1 more2022-07-13
CVE-2022-20212 [HIGH] CWE-1021 CVE-2022-20212: In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjackin In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-182282630
nvd
CVE-2021-25365P3HIGHCVSS 7.8v8.1v9.0+2 more2021-04-09
CVE-2021-25365 [HIGH] CWE-269 CVE-2021-25365: An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applic An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.
nvd
CVE-2022-20271P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20271 [HIGH] CVE-2022-20271: In PermissionController, there is a possible way to grant some permissions without user consent due In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-207672635
nvd
CVE-2022-20331P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20331 [HIGH] CWE-1021 CVE-2022-20331: In the Framework, there is a possible way to enable a work profile without user consent due to a tap In the Framework, there is a possible way to enable a work profile without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-181785557
nvd
CVE-2021-25412P3HIGHCVSS 7.8v10.02021-06-11
CVE-2021-25412 [HIGH] CWE-284 CVE-2021-25412: An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.
nvd
CVE-2022-20282P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20282 [HIGH] CWE-862 CVE-2022-20282: In AppWidget, there is a possible way to start an activity from the background due to a missing perm In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204083104
nvd
CVE-2022-33704P3HIGHCVSS 7.8v10.0v11.0+1 more2022-07-12
CVE-2022-33704 [HIGH] CWE-20 CVE-2022-33704: Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 all Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2022-20250P3HIGHCVSS 7.8v13.0.0vAndroid-132022-08-11
CVE-2022-20250 [HIGH] CVE-2022-20250: In Messaging, there is a possible way to attach files to a message without proper access checks due In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226134095
nvd
Google Android vulnerabilities | cvebase