Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 189 of 483
CVE-2022-22059HIGHCVSS 8.42022-08-01
CVE-2022-22059 [HIGH] CVE-2022-22059: Closed-source component Android Security Bulletin 2022-08-01 CVE: CVE-2022-22059 Severity: HIGH Component: Closed-source component References: A-231156126*
android
CVE-2022-22067HIGHCVSS 7.52022-08-01
CVE-2022-22067 [HIGH] CVE-2022-22067: Closed-source component Android Security Bulletin 2022-08-01 CVE: CVE-2022-22067 Severity: HIGH Component: Closed-source component References: A-218338889*
android
CVE-2022-26435MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26435 [MEDIUM] CWE-787 CVE-2022-26435: In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138435; Issue ID: ALPS07138435.
nvd
CVE-2022-26434MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26434 [MEDIUM] CWE-787 CVE-2022-26434: In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead t In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138450; Issue ID: ALPS07138450.
nvd
CVE-2022-21790MEDIUMCVSS 4.4v11.0v12.02022-08-01
CVE-2022-21790 [MEDIUM] CWE-125 CVE-2022-21790: In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479306; Issue ID: ALPS06479306.
nvd
CVE-2022-21789MEDIUMCVSS 6.4v11.0v12.02022-08-01
CVE-2022-21789 [MEDIUM] CWE-362 CVE-2022-21789: In audio ipi, there is a possible memory corruption due to a race condition. This could lead to loca In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: ALPS06478101.
nvd
CVE-2022-26431MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26431 [MEDIUM] CWE-787 CVE-2022-26431: In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead t In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032553; Issue ID: ALPS07032553.
nvd
CVE-2022-26436MEDIUMCVSS 4.4v12.02022-08-01
CVE-2022-26436 [MEDIUM] CWE-125 CVE-2022-26436: In emi mpu, there is a possible out of bounds read due to a missing bounds check. This could lead to In emi mpu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07023666; Issue ID: ALPS07023666.
nvd
CVE-2022-26430MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26430 [MEDIUM] CWE-787 CVE-2022-26430: In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032521; Issue ID: ALPS07032521.
nvd
CVE-2022-21791MEDIUMCVSS 4.4v11.0v12.02022-08-01
CVE-2022-21791 [MEDIUM] CWE-125 CVE-2022-21791: In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478059; Issue ID: ALPS06478059.
nvd
CVE-2022-21788MEDIUMCVSS 6.7v12.02022-08-01
CVE-2022-21788 [MEDIUM] CVE-2022-21788: In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to l In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06988728; Issue ID: ALPS06988728.
nvd
CVE-2022-26432MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26432 [MEDIUM] CWE-787 CVE-2022-26432: In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead t In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032542; Issue ID: ALPS07032542.
nvd
CVE-2022-26426MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26426 [MEDIUM] CWE-787 CVE-2022-26426: In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lea In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085486; Issue ID: ALPS07085486.
nvd
CVE-2022-26428MEDIUMCVSS 6.4v11.0v12.02022-08-01
CVE-2022-26428 [MEDIUM] CWE-362 CVE-2022-26428: In video codec, there is a possible memory corruption due to a race condition. This could lead to lo In video codec, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521260; Issue ID: ALPS06521260.
nvd
CVE-2022-21792MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-21792 [MEDIUM] CWE-787 CVE-2022-21792: In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lea In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085410; Issue ID: ALPS07085410.
nvd
CVE-2022-26427MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26427 [MEDIUM] CWE-787 CVE-2022-26427: In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lea In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07085540; Issue ID: ALPS07085540.
nvd
CVE-2022-26433MEDIUMCVSS 6.7v11.0v12.02022-08-01
CVE-2022-26433 [MEDIUM] CWE-843 CVE-2022-26433: In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138400; Issue ID: ALPS07138400.
nvd
CVE-2022-20222CRITICALCVSS 9.8v12.0v12.1+1 more2022-07-13
CVE-2022-20222 [CRITICAL] CWE-787 CVE-2022-20222: In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds ch In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-228078096
nvdandroid
CVE-2022-20229CRITICALCVSS 9.8v10.0v11.0+3 more2022-07-13
CVE-2022-20229 [CRITICAL] CWE-787 CVE-2022-20229: In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds wri In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid
nvdandroid
CVE-2022-20224HIGHCVSS 7.5v10.0v11.0+3 more2022-07-13
CVE-2022-20224 [HIGH] CWE-125 CVE-2022-20224: In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect b In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAn
nvdandroid