Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 130 of 483
CVE-2023-20710MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20710 [MEDIUM] CWE-20 CVE-2023-20710: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07576935; Issue ID: ALPS07576935.
nvd
CVE-2023-20694MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20694 [MEDIUM] CWE-787 CVE-2023-20694: In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT6890 only); Issue ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT689
nvdandroid
CVE-2023-21118MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21118 [MEDIUM] CWE-125 CVE-2023-21118: In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overf
In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004
nvdandroid
CVE-2023-20704MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20704 [MEDIUM] CWE-20 CVE-2023-20704: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.
nvd
CVE-2023-21112MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21112 [MEDIUM] CWE-125 CVE-2023-21112: In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds
In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252763983
nvdandroid
CVE-2023-21104MEDIUMCVSS 5.5v12.1v13.0+1 more2023-05-15
CVE-2023-21104 [MEDIUM] CWE-276 CVE-2023-21104: In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local info
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-259938771
nvdandroid
CVE-2023-20698MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20698 [MEDIUM] CWE-125 CVE-2023-20698: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07589144; Issue ID: ALPS07589144.
nvdandroid
CVE-2023-21111MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21111 [MEDIUM] CWE-20 CVE-2023-21111: In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L A
nvdandroid
CVE-2023-20697MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20697 [MEDIUM] CWE-125 CVE-2023-20697: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07589148; Issue ID: ALPS07589148.
nvdandroid
CVE-2023-20711MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20711 [MEDIUM] CWE-125 CVE-2023-20711: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07581668; Issue ID: ALPS07581668.
nvd
CVE-2023-20673MEDIUMCVSS 6.7v11.0v12.0+1 more2023-05-15
CVE-2023-20673 [MEDIUM] CWE-843 CVE-2023-20673: In vcu, there is a possible memory corruption due to type confusion. This could lead to local escala
In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519103.
nvd
CVE-2023-20718MEDIUMCVSS 6.7v11.0v12.0+1 more2023-05-15
CVE-2023-20718 [MEDIUM] CWE-20 CVE-2023-20718: In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645181; Issue ID: ALPS07645181.
nvd
CVE-2023-21116MEDIUMCVSS 6.7v11.0v12.0+3 more2023-05-15
CVE-2023-21116 [MEDIUM] CWE-863 CVE-2023-21116: In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade sys
In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Androi
nvdandroid
CVE-2023-20699MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20699 [MEDIUM] CWE-787 CVE-2023-20699: In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07696073; Issue ID: ALPS07696073.
nvdandroid
CVE-2023-20709MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20709 [MEDIUM] CWE-20 CVE-2023-20709: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07576951; Issue ID: ALPS07576951.
nvd
CVE-2023-20914MEDIUMCVSS 5.5v11.0vAndroid-112023-05-15
CVE-2023-20914 [MEDIUM] CWE-312 CVE-2023-20914: In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a
In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro
nvdandroid
CVE-2023-20930MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-20930 [MEDIUM] CWE-400 CVE-2023-20930: In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boo
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android
nvdandroid
CVE-2023-20707MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20707 [MEDIUM] CWE-20 CVE-2023-20707: In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628556; Issue ID: ALPS07628556.
nvd
CVE-2023-20701MEDIUMCVSS 6.7v11.0v12.02023-05-15
CVE-2023-20701 [MEDIUM] CWE-787 CVE-2023-20701: In widevine, there is a possible out of bounds write due to a logic error. This could lead to local
In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07643270; Issue ID: ALPS07643270.
nvd
CVE-2023-20706MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20706 [MEDIUM] CWE-125 CVE-2023-20706: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.
nvd