cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 181 of 339
CVE-2023-21244P4MEDIUMCVSS 6.7v11.0v12.0+6 more2023-10-06
CVE-2023-21244 [MEDIUM] CWE-862 CVE-2023-21244: In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a mi In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20755P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-07-04
CVE-2023-20755 [MEDIUM] CWE-190 CVE-2023-20755: In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead t In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07509605.
nvd
CVE-2021-0657P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0657 [MEDIUM] CWE-787 CVE-2021-0657: In apusys, there is a possible out of bounds write due to a stack-based buffer overflow. This could In apusys, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672103; Issue ID: ALPS05672103.
nvd
CVE-2022-20539P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20539 [MEDIUM] CWE-787 CVE-2022-20539: In parameterToHal of Effect.cpp, there is a possible out of bounds write due to a missing bounds che In parameterToHal of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the audio server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-237291425
nvd
CVE-2021-0370P4MEDIUMCVSS 6.7v11.0vAndroid-112021-03-10
CVE-2021-0370 [MEDIUM] CWE-787 CVE-2021-0370: In Write of NxpMfcReader.cc, there is a possible out of bounds write due to a missing bounds check. In Write of NxpMfcReader.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169259605
nvd
CVE-2022-20546P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20546 [MEDIUM] CWE-787 CVE-2022-20546: In getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing boun In getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240266798
nvd
CVE-2022-42542P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-42542 [MEDIUM] CWE-787 CVE-2022-42542: In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231445184
nvd
CVE-2021-0671P4MEDIUMCVSS 6.7v10.02021-11-18
CVE-2021-0671 [MEDIUM] CWE-787 CVE-2021-0671: In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to l In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05664273; Issue ID: ALPS05664273.
nvd
CVE-2023-35693P4MEDIUMCVSS 6.7vAndroid kernel2023-07-13
CVE-2023-35693 [MEDIUM] CWE-416 CVE-2023-35693: In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. T In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0543P4MEDIUMCVSS 6.7v11.0vAndroid-112021-06-22
CVE-2021-0543 [MEDIUM] CWE-190 CVE-2021-0543: In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258743
nvd
CVE-2021-0545P4MEDIUMCVSS 6.7v11.0vAndroid-112021-06-22
CVE-2021-0545 [MEDIUM] CWE-787 CVE-2021-0545: In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258884
nvd
CVE-2022-20049P4MEDIUMCVSS 6.7v10.0v11.02022-03-10
CVE-2022-20049 [MEDIUM] CWE-862 CVE-2022-20049: In vpu, there is a possible escalation of privilege due to a missing permission check. This could le In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05954679; Issue ID: ALPS05954679.
nvd
CVE-2023-20634P4MEDIUMCVSS 6.7v11.0v12.02023-03-07
CVE-2023-20634 [MEDIUM] CWE-20 CVE-2023-20634: In widevine, there is a possible out of bounds write due to improper input validation. This could le In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07635697; Issue ID: ALPS07635697.
nvd
CVE-2021-0679P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0679 [MEDIUM] CWE-787 CVE-2021-0679: In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to l In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05687781.
nvd
CVE-2021-0901P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0901 [MEDIUM] CWE-190 CVE-2021-0901: In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to l In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05664618.
nvd
CVE-2024-20013P4MEDIUMCVSS 6.7v11.0v12.0+2 more2024-02-05
CVE-2024-20013 [MEDIUM] CWE-787 CVE-2024-20013: In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08471742; Issue ID: ALPS08308608.
nvd
CVE-2024-20002P4MEDIUMCVSS 6.7v11.0v12.0+2 more2024-02-05
CVE-2024-20002 [MEDIUM] CWE-787 CVE-2024-20002: In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961715; Issue ID: DTV03961715.
nvd
CVE-2021-25503P4MEDIUMCVSS 6.7v8.1v9.0+2 more2021-11-05
CVE-2021-25503 [MEDIUM] CWE-20 CVE-2021-25503: Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
nvd
CVE-2023-32865P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32865 [MEDIUM] CWE-787 CVE-2023-32865: In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could In display drm, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363456; Issue ID: ALPS07363456.
nvd
CVE-2023-32869P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32869 [MEDIUM] CWE-787 CVE-2023-32869: In display drm, there is a possible out of bounds write due to a missing bounds check. This could le In display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363632; Issue ID: ALPS07363689.
nvd
Google Android vulnerabilities | cvebase