Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 130 of 483
CVE-2023-20710MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20710 [MEDIUM] CWE-20 CVE-2023-20710: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07576935; Issue ID: ALPS07576935.
nvd
CVE-2023-20694MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20694 [MEDIUM] CWE-787 CVE-2023-20694: In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT6890 only); Issue ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT689
nvdandroid
CVE-2023-21118MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21118 [MEDIUM] CWE-125 CVE-2023-21118: In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overf In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004
nvdandroid
CVE-2023-20704MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20704 [MEDIUM] CWE-20 CVE-2023-20704: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.
nvd
CVE-2023-21112MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21112 [MEDIUM] CWE-125 CVE-2023-21112: In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252763983
nvdandroid
CVE-2023-21104MEDIUMCVSS 5.5v12.1v13.0+1 more2023-05-15
CVE-2023-21104 [MEDIUM] CWE-276 CVE-2023-21104: In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local info In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-259938771
nvdandroid
CVE-2023-20698MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20698 [MEDIUM] CWE-125 CVE-2023-20698: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07589144; Issue ID: ALPS07589144.
nvdandroid
CVE-2023-21111MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21111 [MEDIUM] CWE-20 CVE-2023-21111: In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L A
nvdandroid
CVE-2023-20697MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20697 [MEDIUM] CWE-125 CVE-2023-20697: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07589148; Issue ID: ALPS07589148.
nvdandroid
CVE-2023-20711MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20711 [MEDIUM] CWE-125 CVE-2023-20711: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07581668; Issue ID: ALPS07581668.
nvd
CVE-2023-20673MEDIUMCVSS 6.7v11.0v12.0+1 more2023-05-15
CVE-2023-20673 [MEDIUM] CWE-843 CVE-2023-20673: In vcu, there is a possible memory corruption due to type confusion. This could lead to local escala In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519103.
nvd
CVE-2023-20718MEDIUMCVSS 6.7v11.0v12.0+1 more2023-05-15
CVE-2023-20718 [MEDIUM] CWE-20 CVE-2023-20718: In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645181; Issue ID: ALPS07645181.
nvd
CVE-2023-21116MEDIUMCVSS 6.7v11.0v12.0+3 more2023-05-15
CVE-2023-21116 [MEDIUM] CWE-863 CVE-2023-21116: In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade sys In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Androi
nvdandroid
CVE-2023-20699MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20699 [MEDIUM] CWE-787 CVE-2023-20699: In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to l In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07696073; Issue ID: ALPS07696073.
nvdandroid
CVE-2023-20709MEDIUMCVSS 4.4v11.0v12.0+1 more2023-05-15
CVE-2023-20709 [MEDIUM] CWE-20 CVE-2023-20709: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07576951; Issue ID: ALPS07576951.
nvd
CVE-2023-20914MEDIUMCVSS 5.5v11.0vAndroid-112023-05-15
CVE-2023-20914 [MEDIUM] CWE-312 CVE-2023-20914: In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro
nvdandroid
CVE-2023-20930MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-20930 [MEDIUM] CWE-400 CVE-2023-20930: In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boo In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android
nvdandroid
CVE-2023-20707MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20707 [MEDIUM] CWE-20 CVE-2023-20707: In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628556; Issue ID: ALPS07628556.
nvd
CVE-2023-20701MEDIUMCVSS 6.7v11.0v12.02023-05-15
CVE-2023-20701 [MEDIUM] CWE-787 CVE-2023-20701: In widevine, there is a possible out of bounds write due to a logic error. This could lead to local In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07643270; Issue ID: ALPS07643270.
nvd
CVE-2023-20706MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20706 [MEDIUM] CWE-125 CVE-2023-20706: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.
nvd