Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 173 of 483
CVE-2022-39113MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39113 [MEDIUM] CWE-862 CVE-2022-39113: In Music service, there is a missing permission check. This could lead to local denial of service in
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2022-39114MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39114 [MEDIUM] CWE-862 CVE-2022-39114: In Music service, there is a missing permission check. This could lead to local denial of service in
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2022-39117MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-39117 [MEDIUM] CWE-862 CVE-2022-39117: In messaging service, there is a missing permission check. This could lead to local information disc
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-39112MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39112 [MEDIUM] CWE-862 CVE-2022-39112: In Music service, there is a missing permission check. This could lead to local denial of service in
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2022-38677MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38677 [MEDIUM] CWE-400 CVE-2022-38677: In cell service, there is a missing permission check. This could lead to local denial of service in
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.
nvd
CVE-2022-38689MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38689 [MEDIUM] CWE-200 CVE-2022-38689: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-39115MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39115 [MEDIUM] CWE-862 CVE-2022-39115: In Music service, there is a missing permission check. This could lead to local denial of service in
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2022-39125MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-39125 [MEDIUM] CWE-400 CVE-2022-39125: In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
nvd
CVE-2022-38688MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38688 [MEDIUM] CWE-200 CVE-2022-38688: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-39103MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-39103 [MEDIUM] CWE-862 CVE-2022-39103: In Gallery service, there is a missing permission check. This could lead to local denial of service
In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service with no additional execution privileges needed.
nvd
CVE-2022-20419HIGHCVSS 7.8v12.1v13.0+1 more2022-10-11
CVE-2022-20419 [HIGH] CVE-2022-20419: In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher
In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-237290578
nvdandroid
CVE-2022-20429HIGHCVSS 8.8v10.0v11.0+3 more2022-10-11
CVE-2022-20429 [HIGH] CVE-2022-20429: In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This
In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220741473
nvd
CVE-2022-20417HIGHCVSS 7.8v12.0v12.1+2 more2022-10-11
CVE-2022-20417 [HIGH] CWE-787 CVE-2022-20417: In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrec
In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237288416
nvdandroid
CVE-2022-20410HIGHCVSS 7.5v10.0v11.0+4 more2022-10-11
CVE-2022-20410 [HIGH] CWE-125 CVE-2022-20410: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an in
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID:
nvdandroid
CVE-2022-20420HIGHCVSS 7.8v13.0vAndroid-132022-10-11
CVE-2022-20420 [HIGH] CVE-2022-20420: In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way
In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way to bypass device policy restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android
nvdandroid
CVE-2022-20418HIGHCVSS 7.5v12.0v12.1+2 more2022-10-11
CVE-2022-20418 [HIGH] CWE-125 CVE-2022-20418: In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds
In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-231986464
nvdandroid
CVE-2022-20416HIGHCVSS 7.8v12.0v12.1+2 more2022-10-11
CVE-2022-20416 [HIGH] CWE-787 CVE-2022-20416: In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrec
In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237717857
nvdandroid
CVE-2022-20415HIGHCVSS 7.8v10.0v11.0+4 more2022-10-11
CVE-2022-20415 [HIGH] CVE-2022-20415: In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass o
In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass of the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A
nvdandroid
CVE-2022-20413MEDIUMCVSS 5.5v10.0v11.0+4 more2022-10-11
CVE-2022-20413 [MEDIUM] CVE-2022-20413: In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic
In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235850634
nvdandroid
CVE-2022-20412MEDIUMCVSS 6.7v10.0v11.0+4 more2022-10-11
CVE-2022-20412 [MEDIUM] CWE-125 CVE-2022-20412: In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. T
In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230794395
nvdandroid