Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 206 of 339
CVE-2021-0344P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-02-04
CVE-2021-0344 [MEDIUM] CVE-2021-0344: In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to
In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05437558.
nvd
CVE-2020-0336P4MEDIUMCVSS 6.7v11.0vAndroid-112020-09-17
CVE-2020-0336 [MEDIUM] CWE-787 CVE-2020-0336: In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to loc
In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153467444
nvd
CVE-2021-0362P4MEDIUMCVSS 6.7v11.0vAndroid-112021-02-03
CVE-2021-0362 [MEDIUM] CWE-787 CVE-2021-0362: In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to loc
In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05457070.
nvd
CVE-2020-0153P4MEDIUMCVSS 6.7v10.0vAndroid-102020-06-11
CVE-2020-0153 [MEDIUM] CWE-787 CVE-2020-0153: In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a mis
In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139733543
nvd
CVE-2020-0186P4MEDIUMCVSS 6.7v10.0vAndroid-102020-06-11
CVE-2020-0186 [MEDIUM] CWE-787 CVE-2020-0186: In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds chec
In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146144463
nvd
CVE-2021-0361P4MEDIUMCVSS 6.7v11.0vAndroid-112021-02-03
CVE-2021-0361 [MEDIUM] CWE-125 CVE-2021-0361: In kisd, there is a possible out of bounds read due to improper input validation. This could lead to
In kisd, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05449968.
nvd
CVE-2020-0330P4MEDIUMCVSS 6.7v11.0vAndroid-112020-09-17
CVE-2020-0330 [MEDIUM] CWE-416 CVE-2020-0330: In iorap, there is a possible memory corruption due to a use after free. This could lead to local es
In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege and code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150331085
nvd
CVE-2020-0003P4MEDIUMCVSS 6.7v8.0vAndroid-8.02020-01-08
CVE-2020-0003 [MEDIUM] CWE-367 CVE-2020-0003: In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-che
In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android ID: A-140195904
nvd
CVE-2022-32614P4MEDIUMCVSS 6.7v12.02022-11-08
CVE-2022-32614 [MEDIUM] CWE-415 CVE-2022-32614: In audio, there is a possible memory corruption due to a logic error. This could lead to local escal
In audio, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310571; Issue ID: ALPS07310571.
nvd
CVE-2022-32620P4MEDIUMCVSS 6.7v10.0v11.0+2 more2022-12-05
CVE-2022-32620 [MEDIUM] CWE-787 CVE-2022-32620: In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalat
In mpu, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07541753; Issue ID: ALPS07541753.
nvd
CVE-2022-32590P4MEDIUMCVSS 6.7v11.0v12.02022-10-07
CVE-2022-32590 [MEDIUM] CWE-754 CVE-2022-32590: In wlan, there is a possible use after free due to an incorrect status check. This could lead to loc
In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425; Issue ID: ALPS07299425.
nvd
CVE-2022-21778P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-11-08
CVE-2022-21778 [MEDIUM] CWE-125 CVE-2022-21778: In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead
In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06382421; Issue ID: ALPS06382421.
nvd
CVE-2022-20064P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-04-11
CVE-2022-20064 [MEDIUM] CWE-125 CVE-2022-20064: In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lea
In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108617; Issue ID: ALPS06108617.
nvd
CVE-2021-0668P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0668 [MEDIUM] CWE-755 CVE-2021-0668: In apusys, there is a possible memory corruption due to incorrect error handling. This could lead to
In apusys, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05670521; Issue ID: ALPS05670521.
nvd
CVE-2021-0634P4MEDIUMCVSS 6.7v11.02021-10-25
CVE-2021-0634 [MEDIUM] CWE-908 CVE-2021-0634: In display driver, there is a possible memory corruption due to uninitialized data. This could lead
In display driver, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594994; Issue ID: ALPS05594994.
nvd
CVE-2021-0898P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0898 [MEDIUM] CWE-416 CVE-2021-0898: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672071.
nvd
CVE-2021-0893P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0893 [MEDIUM] CWE-416 CVE-2021-0893: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05687474.
nvd
CVE-2021-0899P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0899 [MEDIUM] CWE-416 CVE-2021-0899: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672059.
nvd
CVE-2021-0667P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0667 [MEDIUM] CWE-416 CVE-2021-0667: In apusys, there is a possible memory corruption due to a use after free. This could lead to local e
In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05670581; Issue ID: ALPS05670581.
nvd
CVE-2021-0664P4MEDIUMCVSS 6.7v10.0v11.02021-11-18
CVE-2021-0664 [MEDIUM] CWE-416 CVE-2021-0664: In ccu, there is a possible memory corruption due to a use after free. This could lead to local esca
In ccu, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827158; Issue ID: ALPS05827158.
nvd