Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 193 of 483
CVE-2022-21782MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21782 [MEDIUM] CWE-787 CVE-2022-21782: In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could le In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704508.
nvd
CVE-2022-21780MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21780 [MEDIUM] CWE-787 CVE-2022-21780: In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could le In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704526.
nvd
CVE-2022-21765MEDIUMCVSS 6.7v10.0v11.0+1 more2022-07-06
CVE-2022-21765 [MEDIUM] CWE-787 CVE-2022-21765: In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to l In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641673.
nvd
CVE-2022-21779MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21779 [MEDIUM] CWE-787 CVE-2022-21779: In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could le In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704393.
nvd
CVE-2022-21771MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21771 [MEDIUM] CWE-362 CVE-2022-21771: In GED driver, there is a possible use after free due to a race condition. This could lead to local In GED driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641585; Issue ID: ALPS06641585.
nvd
CVE-2022-22096CRITICALCVSS 9.82022-07-01
CVE-2022-22096 [CRITICAL] CVE-2022-22096: Bluetooth Android Security Bulletin 2022-07-01 CVE: CVE-2022-22096 Severity: CRITICAL Component: Bluetooth References: A-213371834 QC-CR#3105585
android
CVE-2022-25658HIGHCVSS 7.32022-07-01
CVE-2022-25658 [HIGH] CVE-2022-25658: Closed-source component Android Security Bulletin 2022-07-01 CVE: CVE-2022-25658 Severity: HIGH Component: Closed-source component References: A-228101855*
android
CVE-2022-22058HIGHCVSS 8.42022-07-01
CVE-2022-22058 [HIGH] CVE-2022-22058: Kernel Android Security Bulletin 2022-07-01 CVE: CVE-2022-22058 Severity: HIGH Component: Kernel References: A-209075540 QC-CR#2747422 QC-CR#2338216
android
CVE-2022-25657HIGHCVSS 7.32022-07-01
CVE-2022-25657 [HIGH] CVE-2022-25657: Closed-source component Android Security Bulletin 2022-07-01 CVE: CVE-2022-25657 Severity: HIGH Component: Closed-source component References: A-228101835*
android
CVE-2022-25659HIGHCVSS 7.32022-07-01
CVE-2022-25659 [HIGH] CVE-2022-25659: Closed-source component Android Security Bulletin 2022-07-01 CVE: CVE-2022-25659 Severity: HIGH Component: Closed-source component References: A-228101819*
android
CVE-2022-20083HIGHCVSS 9.82022-07-01
CVE-2022-20083 [CRITICAL] CVE-2022-20083: Modem 2G/3G CC Android Security Bulletin 2022-07-01 CVE: CVE-2022-20083 Severity: HIGH Component: Modem 2G/3G CC References: A-231275475 M-MOLY00803883*
android
CVE-2022-20236HIGHCVSS 7.52022-07-01
CVE-2022-20236 [HIGH] CVE-2022-20236: gpu Android Security Bulletin 2022-07-01 CVE: CVE-2022-20236 Severity: HIGH Component: gpu References: A-233124709 U-1883940*
android
CVE-2022-20238HIGHCVSS 9.82022-07-01
CVE-2022-20238 [CRITICAL] CVE-2022-20238: kernel Android Security Bulletin 2022-07-01 CVE: CVE-2022-20238 Severity: HIGH Component: kernel References: A-233154555 U-1883892*
android
CVE-2022-21744HIGHCVSS 9.82022-07-01
CVE-2022-21744 [CRITICAL] CVE-2022-21744: Modem 2G RR Android Security Bulletin 2022-07-01 CVE: CVE-2022-21744 Severity: HIGH Component: Modem 2G RR References: A-231281131 M-MOLY00810064*
android
CVE-2022-20216HIGHCVSS 9.82022-07-01
CVE-2022-20216 [CRITICAL] CVE-2022-20216: Telephony Android Security Bulletin 2022-07-01 CVE: CVE-2022-20216 Severity: HIGH Component: Telephony References: A-231911916 U-1867981*
android
CVE-2022-20227HIGHCVSS 5.52022-07-01
CVE-2022-20227 [MEDIUM] CVE-2022-20227: Kernel Android Security Bulletin 2022-07-01 CVE: CVE-2022-20227 Severity: HIGH Type: ID Component: Kernel References: A-216825460 Upstream kernel [2]
android
CVE-2022-20217HIGHCVSS 6.52022-07-01
CVE-2022-20217 [MEDIUM] CVE-2022-20217: Telephony Android Security Bulletin 2022-07-01 CVE: CVE-2022-20217 Severity: HIGH Component: Telephony References: A-232441378 U-1882905*
android
CVE-2022-20130CRITICALCVSS 9.8v10.0v11.0+3 more2022-06-15
CVE-2022-20130 [CRITICAL] CWE-754 CVE-2022-20130: In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a h In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-2243149
nvdandroid
CVE-2022-20127CRITICALCVSS 9.8v10.0v11.0+3 more2022-06-15
CVE-2022-20127 [CRITICAL] CWE-415 CVE-2022-20127: In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. Thi In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221862119
nvdandroid
CVE-2022-20140CRITICALCVSS 9.8v12.0v12.1+1 more2022-06-15
CVE-2022-20140 [CRITICAL] CWE-787 CVE-2022-20140: In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-227618988
nvdandroid