cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 180 of 339
CVE-2019-9318P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9318 [MEDIUM] CWE-909 CVE-2019-9318: In libhevc, there is a missing variable initialization. This could lead to remote information disclo In libhevc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111764725
nvd
CVE-2019-9313P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9313 [MEDIUM] CWE-909 CVE-2019-9313: In libstagefright, there is a missing variable initialization. This could lead to remote information In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112005441
nvd
CVE-2019-9315P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9315 [MEDIUM] CWE-909 CVE-2019-9315: In libhevc, there is a missing variable initialization. This could lead to remote information disclo In libhevc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112326216
nvd
CVE-2019-9321P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9321 [MEDIUM] CWE-909 CVE-2019-9321: In libavc, there is a missing variable initialization. This could lead to remote information disclos In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111208713
nvd
CVE-2019-9316P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9316 [MEDIUM] CWE-909 CVE-2019-9316: In libstagefright, there is a missing variable initialization. This could lead to remote information In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112052432
nvd
CVE-2024-20006P4MEDIUMCVSS 6.7v11.02024-02-05
CVE-2024-20006 [MEDIUM] CWE-787 CVE-2024-20006: In da, there is a possible out of bounds write due to a missing bounds check. This could lead to loc In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: ALPS08477148.
nvd
CVE-2020-0488P4MEDIUMCVSS 6.5v11.0vAndroid-112020-12-15
CVE-2020-0488 [MEDIUM] CWE-200 CVE-2020-0488: In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158484516
nvd
CVE-2020-0491P4MEDIUMCVSS 6.5v11.0vAndroid-112020-12-15
CVE-2020-0491 [MEDIUM] CWE-401 CVE-2020-0491: In readBlock of MatroskaExtractor.cpp, there is a possible denial of service due to resource exhaust In readBlock of MatroskaExtractor.cpp, there is a possible denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156819528
nvd
CVE-2019-9372P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9372 [MEDIUM] CWE-252 CVE-2019-9372: In libskia, there is a possible crash due to a missing null check. This could lead to remote denial In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132782448
nvd
CVE-2022-20509P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20509 [MEDIUM] CWE-787 CVE-2022-20509: In mapGrantorDescr of MessageQueueBase.h, there is a possible out of bounds write due to a missing b In mapGrantorDescr of MessageQueueBase.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244713317
nvd
CVE-2023-21264P4MEDIUMCVSS 6.7vAndroid kernel2023-08-14
CVE-2023-21264 [MEDIUM] CWE-119 CVE-2023-21264: In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-27036P4MEDIUMCVSS 6.7v11.0vAndroid-112020-12-15
CVE-2020-27036 [MEDIUM] CWE-125 CVE-2020-27036: In phNxpNciHal_send_ext_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a In phNxpNciHal_send_ext_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153731369
nvd
CVE-2022-28781P4MEDIUMCVSS 6.7v11.0v12.02022-05-03
CVE-2022-28781 [MEDIUM] CWE-20 CVE-2022-28781: Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arb Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.
nvd
CVE-2017-13233P4MEDIUMCVSS 6.5v5.1.1v6.0+6 more2018-02-12
CVE-2017-13233 [MEDIUM] CWE-400 CVE-2017-13233: In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This coul In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-62851602.
nvd
CVE-2022-32603P4MEDIUMCVSS 6.7v12.02022-11-08
CVE-2022-32603 [MEDIUM] CWE-787 CVE-2022-32603: In gpu drm, there is a possible out of bounds write due to improper input validation. This could lea In gpu drm, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310704; Issue ID: ALPS07310704.
nvd
CVE-2022-26474P4MEDIUMCVSS 6.7v12.02022-10-07
CVE-2022-26474 [MEDIUM] CWE-131 CVE-2022-26474: In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07129717; Issue ID: ALPS07129717.
nvd
CVE-2022-20030P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-02-09
CVE-2022-20030 [MEDIUM] CWE-787 CVE-2022-20030: In vow driver, there is a possible out of bounds write due to a stack-based buffer overflow. This co In vow driver, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05837793; Issue ID: ALPS05837793.
nvd
CVE-2022-20454P4MEDIUMCVSS 6.7v10.0v11.0+4 more2022-11-08
CVE-2022-20454 [MEDIUM] CWE-190 CVE-2022-20454: In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This c In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242096164
nvd
CVE-2022-32622P4MEDIUMCVSS 6.7v11.0v12.0+1 more2022-12-05
CVE-2022-32622 [MEDIUM] CWE-787 CVE-2022-32622: In gz, there is a possible memory corruption due to a missing bounds check. This could lead to local In gz, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363786; Issue ID: ALPS07363786.
nvd
CVE-2022-32630P4MEDIUMCVSS 6.7v12.0v13.02022-12-05
CVE-2022-32630 [MEDIUM] CWE-131 CVE-2022-32630: In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer siz In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405966; Issue ID: ALPS07405966.
nvd
Google Android vulnerabilities | cvebase