cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 201 of 339
CVE-2023-20749P4MEDIUMCVSS 6.7v13.02023-06-06
CVE-2023-20749 [MEDIUM] CWE-787 CVE-2023-20749: In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to l In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07780926.
nvd
CVE-2023-20628P4MEDIUMCVSS 6.7v12.0v13.02023-03-07
CVE-2023-20628 [MEDIUM] CWE-248 CVE-2023-20628: In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to l In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494460; Issue ID: ALPS07494460.
nvd
CVE-2023-20626P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-03-07
CVE-2023-20626 [MEDIUM] CWE-20 CVE-2023-20626: In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead t In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405223; Issue ID: ALPS07405223.
nvd
CVE-2025-20698P4MEDIUMCVSS 6.7v13.0v14.0+1 more2025-08-04
CVE-2025-20698 [MEDIUM] CWE-787 CVE-2025-20698: In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09915400; Issue ID: MSV-3793.
nvd
CVE-2025-20697P4MEDIUMCVSS 6.7v14.0v15.02025-08-04
CVE-2025-20697 [MEDIUM] CWE-787 CVE-2025-20697: In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09915681; Issue ID: MSV-3795.
nvd
CVE-2024-20059P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2024-20059 [MEDIUM] CWE-1332 CVE-2024-20059: In da, there is a possible escalation of privilege due to an incorrect status check. This could lead In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.
nvd
CVE-2024-20056P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2024-20056 [MEDIUM] CWE-20 CVE-2024-20056: In preloader, there is a possible escalation of privilege due to an insecure default value. This cou In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.
nvd
CVE-2024-20012P4MEDIUMCVSS 6.7v12.0v13.02024-02-05
CVE-2024-20012 [MEDIUM] CWE-843 CVE-2024-20012: In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.
nvd
CVE-2023-20837P4MEDIUMCVSS 6.7v12.0v13.02023-09-04
CVE-2023-20837 [MEDIUM] CWE-787 CVE-2023-20837: In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07992786; Issue ID: ALPS07992786.
nvd
CVE-2023-21116P4MEDIUMCVSS 6.7v11.0v12.0+3 more2023-05-15
CVE-2023-21116 [MEDIUM] CWE-863 CVE-2023-21116: In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade sys In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Androi
nvd
CVE-2021-0897P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0897 [MEDIUM] CWE-367 CVE-2021-0897: In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05670549.
nvd
CVE-2023-20724P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-06-06
CVE-2023-20724 [MEDIUM] CWE-125 CVE-2023-20724: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue ID: ALPS07843841.
nvd
CVE-2023-20723P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-06-06
CVE-2023-20723 [MEDIUM] CWE-125 CVE-2023-20723: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue ID: ALPS07843845.
nvd
CVE-2023-20699P4MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20699 [MEDIUM] CWE-787 CVE-2023-20699: In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to l In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07696073; Issue ID: ALPS07696073.
nvd
CVE-2023-32818P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-11-06
CVE-2023-32818 [MEDIUM] CWE-843 CVE-2023-32818: In vdec, there is a possible out of bounds write due to type confusion. This could lead to local esc In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896 & ALPS08013430; Issue ID: ALPS07867715.
nvd
CVE-2023-32830P4MEDIUMCVSS 6.7v10.0v11.02023-10-02
CVE-2023-32830 [MEDIUM] CWE-787 CVE-2023-32830: In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03802522; Issue ID: DTV03802522.
nvd
CVE-2023-20804P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20804 [MEDIUM] CWE-787 CVE-2023-20804: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384.
nvd
CVE-2023-20795P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20795 [MEDIUM] CWE-787 CVE-2023-20795: In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07864900; Issue ID: ALPS07864900.
nvd
CVE-2023-20807P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20807 [MEDIUM] CWE-787 CVE-2023-20807: In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608433; Issue ID: ALPS07608433.
nvd
CVE-2023-20786P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20786 [MEDIUM] CWE-787 CVE-2023-20786: In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ALPS07767811.
nvd
Google Android vulnerabilities | cvebase