Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 183 of 339
CVE-2023-20994P4MEDIUMCVSS 6.7v13.0vAndroid-132023-03-24
CVE-2023-20994 [MEDIUM] CWE-787 CVE-2023-20994: In _ufdt_output_property_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an
In _ufdt_output_property_to_fdt of ufdt_convert.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259062118
nvd
CVE-2023-32872P4MEDIUMCVSS 6.7v11.0v12.0+1 more2024-01-02
CVE-2023-32872 [MEDIUM] CWE-787 CVE-2023-32872: In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08308607.
nvd
CVE-2023-32883P4MEDIUMCVSS 6.7v12.0v13.02024-01-02
CVE-2023-32883 [MEDIUM] CWE-787 CVE-2023-32883: In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could
In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08282249; Issue ID: ALPS08282249.
nvd
CVE-2023-32885P4MEDIUMCVSS 6.7v12.0v13.02024-01-02
CVE-2023-32885 [MEDIUM] CWE-119 CVE-2023-32885: In display drm, there is a possible memory corruption due to a missing bounds check. This could lead
In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issue ID: ALPS07780685.
nvd
CVE-2023-20756P4MEDIUMCVSS 6.7v12.0v13.02023-07-04
CVE-2023-20756 [MEDIUM] CWE-190 CVE-2023-20756: In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead t
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07549928.
nvd
CVE-2023-20725P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20725 [MEDIUM] CWE-787 CVE-2023-20725: In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07734004 / ALPS07874358 (For MT6880, MT6890, MT6980, MT6990 only); Issue ID: ALPS07734004 / ALPS07874358 (For MT6
nvd
CVE-2023-20694P4MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20694 [MEDIUM] CWE-787 CVE-2023-20694: In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT6890 only); Issue ID: ALPS07733998 / ALPS07874388 (For MT6880 and MT689
nvd
CVE-2023-20695P4MEDIUMCVSS 6.7v13.02023-05-15
CVE-2023-20695 [MEDIUM] CWE-787 CVE-2023-20695: In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead
In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07734012 / ALPS07874363 (For MT6880, MT6890, MT6980 and MT6990 only); Issue ID: ALPS07734012 / ALPS07874363 (For
nvd
CVE-2023-20681P4MEDIUMCVSS 6.7v12.0v13.02023-04-06
CVE-2023-20681 [MEDIUM] CWE-787 CVE-2023-20681: In adsp, there is a possible out of bounds write due to improper input validation. This could lead t
In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07696134; Issue ID: ALPS07696134.
nvd
CVE-2022-32624P4MEDIUMCVSS 6.7v11.0v12.02022-12-05
CVE-2022-32624 [MEDIUM] CWE-131 CVE-2022-32624: In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer siz
In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405923; Issue ID: ALPS07405923.
nvd
CVE-2023-21370P4MEDIUMCVSS 6.7fixed in 14.0v142023-10-30
CVE-2023-21370 [MEDIUM] CWE-190 CVE-2023-21370: In the Security Element API, there is a possible out of bounds write due to an integer overflow. Thi
In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21371P4MEDIUMCVSS 6.7fixed in 14.0v142023-10-30
CVE-2023-21371 [MEDIUM] CWE-190 CVE-2023-21371: In Secure Element, there is a possible out of bounds write due to an integer overflow. This could le
In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35655P4MEDIUMCVSS 6.7vAndroid kernel2023-10-11
CVE-2023-35655 [MEDIUM] CWE-125 CVE-2023-35655: In CanConvertPadV2Op of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds read due t
In CanConvertPadV2Op of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-32879P4MEDIUMCVSS 6.7v12.0v13.02024-01-02
CVE-2023-32879 [MEDIUM] CWE-787 CVE-2023-32879: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308064.
nvd
CVE-2023-32877P4MEDIUMCVSS 6.7v12.0v13.02024-01-02
CVE-2023-32877 [MEDIUM] CWE-787 CVE-2023-32877: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308070.
nvd
CVE-2023-35660P4MEDIUMCVSS 6.7vAndroid kernel2023-10-11
CVE-2023-35660 [MEDIUM] CWE-416 CVE-2023-35660: In lwis_transaction_client_cleanup of lwis_transaction.c, there is a possible way to corrupt memory
In lwis_transaction_client_cleanup of lwis_transaction.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35654P4MEDIUMCVSS 6.7vAndroid kernel2023-10-11
CVE-2023-35654 [MEDIUM] CWE-125 CVE-2023-35654: In ctrl_roi of stmvl53l1_module.c, there is a possible out of bounds read due to an incorrect bounds
In ctrl_roi of stmvl53l1_module.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-32806P4MEDIUMCVSS 6.7v12.0v13.02023-09-04
CVE-2023-32806 [MEDIUM] CWE-787 CVE-2023-32806: In wlan driver, there is a possible out of bounds write due to improper input validation. This could
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589; Issue ID: ALPS07441589.
nvd
CVE-2023-32811P4MEDIUMCVSS 6.7v12.0v13.02023-09-04
CVE-2023-32811 [MEDIUM] CWE-787 CVE-2023-32811: In connectivity system driver, there is a possible out of bounds write due to improper input validat
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.
nvd
CVE-2023-32835P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-11-06
CVE-2023-32835 [MEDIUM] CWE-843 CVE-2023-32835: In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local
In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; Issue ID: ALPS08157918.
nvd