Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 193 of 483
CVE-2022-21782MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21782 [MEDIUM] CWE-787 CVE-2022-21782: In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could le
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704508.
nvd
CVE-2022-21780MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21780 [MEDIUM] CWE-787 CVE-2022-21780: In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could le
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704526.
nvd
CVE-2022-21765MEDIUMCVSS 6.7v10.0v11.0+1 more2022-07-06
CVE-2022-21765 [MEDIUM] CWE-787 CVE-2022-21765: In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641673.
nvd
CVE-2022-21779MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21779 [MEDIUM] CWE-787 CVE-2022-21779: In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could le
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704393.
nvd
CVE-2022-21771MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21771 [MEDIUM] CWE-362 CVE-2022-21771: In GED driver, there is a possible use after free due to a race condition. This could lead to local
In GED driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641585; Issue ID: ALPS06641585.
nvd
CVE-2022-22096CRITICALCVSS 9.82022-07-01
CVE-2022-22096 [CRITICAL] CVE-2022-22096: Bluetooth
Android Security Bulletin 2022-07-01
CVE: CVE-2022-22096
Severity: CRITICAL
Component: Bluetooth
References: A-213371834
QC-CR#3105585
android
CVE-2022-25658HIGHCVSS 7.32022-07-01
CVE-2022-25658 [HIGH] CVE-2022-25658: Closed-source component
Android Security Bulletin 2022-07-01
CVE: CVE-2022-25658
Severity: HIGH
Component: Closed-source component
References: A-228101855*
android
CVE-2022-22058HIGHCVSS 8.42022-07-01
CVE-2022-22058 [HIGH] CVE-2022-22058: Kernel
Android Security Bulletin 2022-07-01
CVE: CVE-2022-22058
Severity: HIGH
Component: Kernel
References: A-209075540
QC-CR#2747422
QC-CR#2338216
android
CVE-2022-25657HIGHCVSS 7.32022-07-01
CVE-2022-25657 [HIGH] CVE-2022-25657: Closed-source component
Android Security Bulletin 2022-07-01
CVE: CVE-2022-25657
Severity: HIGH
Component: Closed-source component
References: A-228101835*
android
CVE-2022-25659HIGHCVSS 7.32022-07-01
CVE-2022-25659 [HIGH] CVE-2022-25659: Closed-source component
Android Security Bulletin 2022-07-01
CVE: CVE-2022-25659
Severity: HIGH
Component: Closed-source component
References: A-228101819*
android
CVE-2022-20083HIGHCVSS 9.82022-07-01
CVE-2022-20083 [CRITICAL] CVE-2022-20083: Modem 2G/3G CC
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20083
Severity: HIGH
Component: Modem 2G/3G CC
References: A-231275475
M-MOLY00803883*
android
CVE-2022-20236HIGHCVSS 7.52022-07-01
CVE-2022-20236 [HIGH] CVE-2022-20236: gpu
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20236
Severity: HIGH
Component: gpu
References: A-233124709
U-1883940*
android
CVE-2022-20238HIGHCVSS 9.82022-07-01
CVE-2022-20238 [CRITICAL] CVE-2022-20238: kernel
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20238
Severity: HIGH
Component: kernel
References: A-233154555
U-1883892*
android
CVE-2022-21744HIGHCVSS 9.82022-07-01
CVE-2022-21744 [CRITICAL] CVE-2022-21744: Modem 2G RR
Android Security Bulletin 2022-07-01
CVE: CVE-2022-21744
Severity: HIGH
Component: Modem 2G RR
References: A-231281131
M-MOLY00810064*
android
CVE-2022-20216HIGHCVSS 9.82022-07-01
CVE-2022-20216 [CRITICAL] CVE-2022-20216: Telephony
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20216
Severity: HIGH
Component: Telephony
References: A-231911916
U-1867981*
android
CVE-2022-20227HIGHCVSS 5.52022-07-01
CVE-2022-20227 [MEDIUM] CVE-2022-20227: Kernel
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20227
Severity: HIGH
Type: ID
Component: Kernel
References: A-216825460
Upstream kernel
[2]
android
CVE-2022-20217HIGHCVSS 6.52022-07-01
CVE-2022-20217 [MEDIUM] CVE-2022-20217: Telephony
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20217
Severity: HIGH
Component: Telephony
References: A-232441378
U-1882905*
android
CVE-2022-20130CRITICALCVSS 9.8v10.0v11.0+3 more2022-06-15
CVE-2022-20130 [CRITICAL] CWE-754 CVE-2022-20130: In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a h
In transportDec_OutOfBandConfig of tpdec_lib.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-2243149
nvdandroid
CVE-2022-20127CRITICALCVSS 9.8v10.0v11.0+3 more2022-06-15
CVE-2022-20127 [CRITICAL] CWE-415 CVE-2022-20127: In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. Thi
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221862119
nvdandroid
CVE-2022-20140CRITICALCVSS 9.8v12.0v12.1+1 more2022-06-15
CVE-2022-20140 [CRITICAL] CWE-787 CVE-2022-20140: In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-227618988
nvdandroid