Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 179 of 339
CVE-2023-21132P4MEDIUMCVSS 6.8v12.0v12.1+4 more2023-08-14
CVE-2023-21132 [MEDIUM] CWE-862 CVE-2023-21132: In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset prote
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21133P4MEDIUMCVSS 6.8v12.0v12.1+4 more2023-08-14
CVE-2023-21133 [MEDIUM] CWE-862 CVE-2023-21133: In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset prote
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21140P4MEDIUMCVSS 6.8v12.0v12.1+4 more2023-08-14
CVE-2023-21140 [MEDIUM] CWE-862 CVE-2023-21140: In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset prote
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21134P4MEDIUMCVSS 6.8v12.0v12.1+4 more2023-08-14
CVE-2023-21134 [MEDIUM] CWE-862 CVE-2023-21134: In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset prote
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-25832P4MEDIUMCVSS 6.8v11.0v12.02022-04-11
CVE-2022-25832 [MEDIUM] CWE-287 CVE-2022-25832: Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical at
Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.
nvd
CVE-2019-9428P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9428 [MEDIUM] CVE-2019-9428: In the Framework, it is possible to set up BROWSEABLE intents to take over certain URLs. This could
In the Framework, it is possible to set up BROWSEABLE intents to take over certain URLs. This could lead to remote information disclosure of sensitive URLs with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110150807
nvd
CVE-2022-20072P4MEDIUMCVSS 6.7v11.0v12.02022-04-11
CVE-2022-20072 [MEDIUM] CWE-697 CVE-2022-20072: In search engine service, there is a possible way to change the default search engine due to an inco
In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06219118; Issue ID: ALPS06219118.
nvd
CVE-2021-0364P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-03
CVE-2021-0364 [MEDIUM] CWE-77 CVE-2021-0364: In mobile_log_d, there is a possible command injection due to improper input validation. This could
In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05458478; Issue ID: ALPS05458503.
nvd
CVE-2021-0363P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-03
CVE-2021-0363 [MEDIUM] CWE-77 CVE-2021-0363: In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lea
In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05458478.
nvd
CVE-2018-9347P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2018-11-14
CVE-2018-9347 [MEDIUM] CWE-20 CVE-2018-9347: In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infi
In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary DoS with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Andro
nvd
CVE-2020-0191P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0191 [MEDIUM] CWE-125 CVE-2020-0191: In ih264d_update_default_index_list() of ih264d_dpb_mgr.c, there is a possible out of bounds read du
In ih264d_update_default_index_list() of ih264d_dpb_mgr.c, there is a possible out of bounds read due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140561484
nvd
CVE-2020-0361P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0361 [MEDIUM] CWE-908 CVE-2020-0361: In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead
In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151927433
nvd
CVE-2020-0340P4MEDIUMCVSS 6.5v11.0vAndroid-112020-09-17
CVE-2020-0340 [MEDIUM] CWE-908 CVE-2020-0340: In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This
In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144901522
nvd
CVE-2020-0212P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0212 [MEDIUM] CWE-125 CVE-2020-0212: In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use
In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-135140854
nvd
CVE-2020-0195P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0195 [MEDIUM] CWE-908 CVE-2020-0195: In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there i
In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A
nvd
CVE-2019-9320P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9320 [MEDIUM] CWE-909 CVE-2019-9320: In libavc, there is a missing variable initialization. This could lead to remote information disclos
In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111761624
nvd
CVE-2019-9317P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9317 [MEDIUM] CWE-909 CVE-2019-9317: In libstagefright, there is a missing variable initialization. This could lead to remote information
In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112052258
nvd
CVE-2019-9247P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9247 [MEDIUM] CWE-909 CVE-2019-9247: In AAC Codec, there is a missing variable initialization. This could lead to remote information disc
In AAC Codec, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120426166
nvd
CVE-2019-9319P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9319 [MEDIUM] CWE-909 CVE-2019-9319: In libavc, there is a missing variable initialization. This could lead to remote information disclos
In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111762100
nvd
CVE-2019-9314P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9314 [MEDIUM] CWE-909 CVE-2019-9314: In libavc, there is a missing variable initialization. This could lead to remote information disclos
In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112329563
nvd