Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 194 of 339
CVE-2023-20766P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-07-04
CVE-2023-20766 [MEDIUM] CWE-787 CVE-2023-20766: In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ALPS07573202.
nvd
CVE-2023-20760P4MEDIUMCVSS 6.7v12.0v13.02023-07-04
CVE-2023-20760 [MEDIUM] CWE-787 CVE-2023-20760: In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629578; Issue ID: ALPS07629578.
nvd
CVE-2023-20775P4MEDIUMCVSS 6.7v12.0v13.02023-07-04
CVE-2023-20775 [MEDIUM] CWE-787 CVE-2023-20775: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07978760; Issue ID: ALPS07363410.
nvd
CVE-2023-20767P4MEDIUMCVSS 6.7v12.0v13.02023-07-04
CVE-2023-20767 [MEDIUM] CWE-787 CVE-2023-20767: In pqframework, there is a possible out of bounds write due to a missing bounds check. This could le
In pqframework, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629585; Issue ID: ALPS07629584.
nvd
CVE-2021-0535P4MEDIUMCVSS 6.7v11.0vAndroid-112021-06-22
CVE-2021-0535 [MEDIUM] CWE-416 CVE-2021-0535: In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a
In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741
nvd
CVE-2022-21765P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-07-06
CVE-2022-21765 [MEDIUM] CWE-787 CVE-2022-21765: In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641673; Issue ID: ALPS06641673.
nvd
CVE-2022-20067P4MEDIUMCVSS 6.7v9.0v10.0+2 more2022-04-11
CVE-2022-20067 [MEDIUM] CWE-787 CVE-2022-20067: In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836585; Issue ID: ALPS05836585.
nvd
CVE-2022-20014P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-01-04
CVE-2022-20014 [MEDIUM] CWE-787 CVE-2022-20014: In vow driver, there is a possible memory corruption due to improper input validation. This could le
In vow driver, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05857308; Issue ID: ALPS05857308.
nvd
CVE-2021-0977P4MEDIUMCVSS 6.7v12.0vAndroid-122021-12-15
CVE-2021-0977 [MEDIUM] CWE-787 CVE-2021-0977: In phNxpNHal_DtaUpdate of phNxpNciHal_dta.cc, there is a possible out of bounds write due to an inco
In phNxpNHal_DtaUpdate of phNxpNciHal_dta.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-183487770
nvd
CVE-2021-1024P4MEDIUMCVSS 6.7v12.0vAndroid-122021-12-15
CVE-2021-1024 [MEDIUM] CVE-2021-1024: In onEventReceived of EventResultPersister.java, there is a possible intent redirection due to a con
In onEventReceived of EventResultPersister.java, there is a possible intent redirection due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191283525
nvd
CVE-2021-0656P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0656 [MEDIUM] CWE-416 CVE-2021-0656: In edma driver, there is a possible memory corruption due to a use after free. This could lead to lo
In edma driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05709376; Issue ID: ALPS05709376.
nvd
CVE-2021-0655P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0655 [MEDIUM] CWE-787 CVE-2021-0655: In mdlactl driver, there is a possible memory corruption due to an incorrect bounds check. This coul
In mdlactl driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05673424; Issue ID: ALPS05673424.
nvd
CVE-2023-20757P4MEDIUMCVSS 6.7v12.0v13.02023-07-04
CVE-2023-20757 [MEDIUM] CWE-787 CVE-2023-20757: In cmdq, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In cmdq, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07636133; Issue ID: ALPS07636133.
nvd
CVE-2023-20708P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-05-15
CVE-2023-20708 [MEDIUM] CWE-20 CVE-2023-20708: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07581655; Issue ID: ALPS07581655.
nvd
CVE-2021-0691P4MEDIUMCVSS 6.7v11.0vAndroid-112021-10-06
CVE-2021-0691 [MEDIUM] CWE-269 CVE-2021-0691: In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain co
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11And
nvd
CVE-2021-25467P4MEDIUMCVSS 6.7v11.02021-10-06
CVE-2021-25467 [MEDIUM] CWE-120 CVE-2021-25467: Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kern
Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.
nvd
CVE-2024-20021P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2024-20021 [MEDIUM] CWE-269 CVE-2024-20021: In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error.
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.
nvd
CVE-2023-42722P4MEDIUMCVSS 6.7v11.02023-12-04
CVE-2023-42722 [MEDIUM] CWE-416 CVE-2023-42722: In camera service, there is a possible use after free due to a logic error. This could lead to local
In camera service, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed
nvd
CVE-2023-32870P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32870 [MEDIUM] CWE-125 CVE-2023-32870: In display drm, there is a possible out of bounds read due to a missing bounds check. This could lea
In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363740; Issue ID: ALPS07363740.
nvd
CVE-2023-32863P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32863 [MEDIUM] CWE-125 CVE-2023-32863: In display drm, there is a possible out of bounds read due to a missing bounds check. This could lea
In display drm, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326314; Issue ID: ALPS07326314.
nvd