cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 206 of 339
CVE-2021-0344P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-04
CVE-2021-0344 [MEDIUM] CVE-2021-0344: In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05437558.
nvd
CVE-2020-0336P4MEDIUMCVSS 6.7v11.0vAndroid-112020-09-17
CVE-2020-0336 [MEDIUM] CWE-787 CVE-2020-0336: In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to loc In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153467444
nvd
CVE-2021-0362P4MEDIUMCVSS 6.7v11.0vAndroid-112021-02-03
CVE-2021-0362 [MEDIUM] CWE-787 CVE-2021-0362: In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to loc In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05457070.
nvd
CVE-2020-0153P4MEDIUMCVSS 6.7v10.0vAndroid-102020-06-11
CVE-2020-0153 [MEDIUM] CWE-787 CVE-2020-0153: In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a mis In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139733543
nvd
CVE-2020-0186P4MEDIUMCVSS 6.7v10.0vAndroid-102020-06-11
CVE-2020-0186 [MEDIUM] CWE-787 CVE-2020-0186: In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds chec In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146144463
nvd
CVE-2021-0361P4MEDIUMCVSS 6.7v11.0vAndroid-112021-02-03
CVE-2021-0361 [MEDIUM] CWE-125 CVE-2021-0361: In kisd, there is a possible out of bounds read due to improper input validation. This could lead to In kisd, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05449968.
nvd
CVE-2020-0330P4MEDIUMCVSS 6.7v11.0vAndroid-112020-09-17
CVE-2020-0330 [MEDIUM] CWE-416 CVE-2020-0330: In iorap, there is a possible memory corruption due to a use after free. This could lead to local es In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege and code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150331085
nvd
CVE-2020-0003P4MEDIUMCVSS 6.7v8.0vAndroid-8.02020-01-08
CVE-2020-0003 [MEDIUM] CWE-367 CVE-2020-0003: In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-che In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android ID: A-140195904
nvd
CVE-2022-32614P4MEDIUMCVSS 6.7v12.02022-11-08
CVE-2022-32614 [MEDIUM] CWE-415 CVE-2022-32614: In audio, there is a possible memory corruption due to a logic error. This could lead to local escal In audio, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310571; Issue ID: ALPS07310571.
nvd
CVE-2022-32620P4MEDIUMCVSS 6.7v10.0v11.0+2 more2022-12-05
CVE-2022-32620 [MEDIUM] CWE-787 CVE-2022-32620: In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalat In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07541753; Issue ID: ALPS07541753.
nvd
CVE-2022-32590P4MEDIUMCVSS 6.7v11.0v12.02022-10-07
CVE-2022-32590 [MEDIUM] CWE-754 CVE-2022-32590: In wlan, there is a possible use after free due to an incorrect status check. This could lead to loc In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425; Issue ID: ALPS07299425.
nvd
CVE-2022-21778P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-11-08
CVE-2022-21778 [MEDIUM] CWE-125 CVE-2022-21778: In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06382421; Issue ID: ALPS06382421.
nvd
CVE-2022-20064P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-04-11
CVE-2022-20064 [MEDIUM] CWE-125 CVE-2022-20064: In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lea In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108617; Issue ID: ALPS06108617.
nvd
CVE-2021-0668P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0668 [MEDIUM] CWE-755 CVE-2021-0668: In apusys, there is a possible memory corruption due to incorrect error handling. This could lead to In apusys, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05670521; Issue ID: ALPS05670521.
nvd
CVE-2021-0634P4MEDIUMCVSS 6.7v11.02021-10-25
CVE-2021-0634 [MEDIUM] CWE-908 CVE-2021-0634: In display driver, there is a possible memory corruption due to uninitialized data. This could lead In display driver, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594994; Issue ID: ALPS05594994.
nvd
CVE-2021-0898P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0898 [MEDIUM] CWE-416 CVE-2021-0898: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672071.
nvd
CVE-2021-0893P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0893 [MEDIUM] CWE-416 CVE-2021-0893: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05687474.
nvd
CVE-2021-0899P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0899 [MEDIUM] CWE-416 CVE-2021-0899: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672059.
nvd
CVE-2021-0667P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0667 [MEDIUM] CWE-416 CVE-2021-0667: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05670581; Issue ID: ALPS05670581.
nvd
CVE-2021-0664P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0664 [MEDIUM] CWE-416 CVE-2021-0664: In ccu, there is a possible memory corruption due to a use after free. This could lead to local esca In ccu, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827158; Issue ID: ALPS05827158.
nvd
Google Android vulnerabilities | cvebase