cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 189 of 339
CVE-2019-9415P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9415 [MEDIUM] CWE-908 CVE-2019-9415: In libstagefright there is a possible information disclosure due to uninitialized data. This could l In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111805098
nvd
CVE-2019-9416P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9416 [MEDIUM] CWE-908 CVE-2019-9416: In libstagefright there is a possible information disclosure due to uninitialized data. This could l In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111804142
nvd
CVE-2018-9509P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9509 [MEDIUM] CWE-125 CVE-2018-9509: In smp_proc_master_id of smp_act.cc, there is a possible out of bounds read due to a missing bounds In smp_proc_master_id of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2018-9510P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9510 [MEDIUM] CWE-125 CVE-2018-9510: In smp_proc_enc_info of smp_act.cc, there is a possible out of bounds read due to a missing bounds c In smp_proc_enc_info of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2022-39083P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39083 [MEDIUM] CWE-77 CVE-2022-39083: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2022-39084P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39084 [MEDIUM] CWE-77 CVE-2022-39084: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2022-39087P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39087 [MEDIUM] CWE-77 CVE-2022-39087: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2022-39081P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39081 [MEDIUM] CWE-77 CVE-2022-39081: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2022-39088P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39088 [MEDIUM] CWE-77 CVE-2022-39088: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2022-39086P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39086 [MEDIUM] CWE-77 CVE-2022-39086: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2022-39085P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39085 [MEDIUM] CWE-77 CVE-2022-39085: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2022-39082P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-01-04
CVE-2022-39082 [MEDIUM] CWE-77 CVE-2022-39082: In network service, there is a missing permission check. This could lead to local escalation of priv In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
nvd
CVE-2020-0347P4MEDIUMCVSS 6.7v11.0vAndroid-112020-09-18
CVE-2020-0347 [MEDIUM] CWE-787 CVE-2020-0347: In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could le In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136658008
nvd
CVE-2020-0005P4MEDIUMCVSS 6.7v8.0v8.1+3 more2020-02-13
CVE-2020-0005 [MEDIUM] CWE-787 CVE-2020-0005: In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-14155
nvd
CVE-2022-20554P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20554 [MEDIUM] CWE-416 CVE-2022-20554: In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. Th In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245770596
nvd
CVE-2022-20557P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20557 [MEDIUM] CWE-125 CVE-2022-20557: In MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing b In MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-247092734
nvd
CVE-2018-9506P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9506 [MEDIUM] CWE-125 CVE-2018-9506: In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds chec In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.
nvd
CVE-2022-20504P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20504 [MEDIUM] CWE-862 CVE-2022-20504: In multiple locations of DreamManagerService.java, there is a missing permission check. This could l In multiple locations of DreamManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and dismissal of system dialogs with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-225878553
nvd
CVE-2019-9259P4MEDIUMCVSS 6.7v10.0vAndroid-102019-09-27
CVE-2019-9259 [MEDIUM] CWE-416 CVE-2019-9259: In the Bluetooth stack, there is a possible out of bounds write due to a use after free. This could In the Bluetooth stack, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113575306
nvd
CVE-2021-0345P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-04
CVE-2021-0345 [MEDIUM] CWE-20 CVE-2021-0345: In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05432974.
nvd
Google Android vulnerabilities | cvebase