Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 191 of 339
CVE-2022-20412P4MEDIUMCVSS 6.7v10.0v11.0+4 more2022-10-11
CVE-2022-20412 [MEDIUM] CWE-125 CVE-2022-20412: In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. T
In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230794395
nvd
CVE-2020-0483P4MEDIUMCVSS 6.7v11.0vAndroid-112020-12-15
CVE-2020-0483 [MEDIUM] CWE-416 CVE-2020-0483: In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corr
In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155647761
nvd
CVE-2020-0484P4MEDIUMCVSS 6.7v11.0vAndroid-112020-12-15
CVE-2020-0484 [MEDIUM] CWE-416 CVE-2020-0484: In destroyResources of ComposerClient.h, there is possible memory corruption due to a use after free
In destroyResources of ComposerClient.h, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155769496
nvd
CVE-2022-32599P4MEDIUMCVSS 6.7v10.0v11.0+2 more2023-04-06
CVE-2022-32599 [MEDIUM] CWE-787 CVE-2022-32599: In rpmb, there is a possible out of bounds write due to a logic error. This could lead to local esca
In rpmb, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460390; Issue ID: ALPS07460390.
nvd
CVE-2020-0309P4MEDIUMCVSS 6.7v11.0vAndroid-112020-09-18
CVE-2020-0309 [MEDIUM] CWE-190 CVE-2020-0309: In the Bluetooth server, there is a possible out of bounds write due to an integer overflow. This co
In the Bluetooth server, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147227320
nvd
CVE-2022-20050P4MEDIUMCVSS 6.7v11.0v12.02022-03-10
CVE-2022-20050 [MEDIUM] CWE-59 CVE-2022-20050: In connsyslogger, there is a possible symbolic link following due to improper link resolution. This
In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06335038; Issue ID: ALPS06335038.
nvd
CVE-2017-13234P4MEDIUMCVSS 6.5v5.1.1v6.0+6 more2018-02-12
CVE-2017-13234 [MEDIUM] CWE-772 CVE-2017-13234: In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. Thi
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68159767.
nvd
CVE-2022-32593P4MEDIUMCVSS 6.7v12.02022-10-07
CVE-2022-32593 [MEDIUM] CWE-787 CVE-2022-32593: In vowe, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In vowe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138493; Issue ID: ALPS07138493.
nvd
CVE-2022-32616P4MEDIUMCVSS 6.7v12.02022-11-08
CVE-2022-32616 [MEDIUM] CWE-908 CVE-2022-32616: In isp, there is a possible out of bounds write due to uninitialized data. This could lead to local
In isp, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341258; Issue ID: ALPS07341258.
nvd
CVE-2022-32611P4MEDIUMCVSS 6.7v11.0v12.02022-11-08
CVE-2022-32611 [MEDIUM] CWE-787 CVE-2022-32611: In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340373; Issue ID: ALPS07340373.
nvd
CVE-2022-32607P4MEDIUMCVSS 6.7v11.0v12.02022-11-08
CVE-2022-32607 [MEDIUM] CWE-416 CVE-2022-32607: In aee, there is a possible use after free due to a missing bounds check. This could lead to local e
In aee, there is a possible use after free due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202891; Issue ID: ALPS07202891.
nvd
CVE-2022-32615P4MEDIUMCVSS 6.7v12.02022-11-08
CVE-2022-32615 [MEDIUM] CWE-908 CVE-2022-32615: In ccd, there is a possible out of bounds write due to uninitialized data. This could lead to local
In ccd, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326559; Issue ID: ALPS07326559.
nvd
CVE-2021-0904P4MEDIUMCVSS 6.7v8.1v9.0+2 more2021-12-15
CVE-2021-0904 [MEDIUM] CWE-732 CVE-2021-0904: In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.
nvd
CVE-2021-0585P4MEDIUMCVSS 6.7v8.1v9.0+3 more2021-07-14
CVE-2021-0585 [MEDIUM] CWE-787 CVE-2021-0585: In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to im
In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-1849633
nvd
CVE-2021-0402P4MEDIUMCVSS 6.7v11.0vAndroid-112021-02-26
CVE-2021-0402 [MEDIUM] CWE-787 CVE-2021-0402: In jpeg, there is a possible out of bounds write due to improper input validation. This could lead t
In jpeg, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05433311.
nvd
CVE-2021-0406P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-26
CVE-2021-0406 [MEDIUM] CWE-787 CVE-2021-0406: In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead
In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05471418.
nvd
CVE-2021-0405P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-26
CVE-2021-0405 [MEDIUM] CWE-787 CVE-2021-0405: In performance driver, there is a possible out of bounds write due to a missing bounds check. This c
In performance driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05466547.
nvd
CVE-2022-20505P4MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20505 [MEDIUM] CWE-22 CVE-2022-20505: In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal e
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitationProduct: AndroidVersions: Android-13Android ID: A-225981754
nvd
CVE-2022-32605P4MEDIUMCVSS 6.7v12.02022-11-08
CVE-2022-32605 [MEDIUM] CWE-787 CVE-2022-32605: In isp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to
In isp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07213898; Issue ID: ALPS07213898.
nvd
CVE-2022-32640P4MEDIUMCVSS 6.7v11.0v12.02023-01-03
CVE-2022-32640 [MEDIUM] CWE-787 CVE-2022-32640: In meta wifi, there is a possible out of bounds write due to a missing bounds check. This could lead
In meta wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441652; Issue ID: ALPS07441652.
nvd