Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 207 of 339
CVE-2023-32862P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32862 [MEDIUM] CWE-125 CVE-2023-32862: In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead
In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issue ID: ALPS07388762.
nvd
CVE-2023-32861P4MEDIUMCVSS 6.7v12.0v13.02023-12-04
CVE-2023-32861 [MEDIUM] CWE-125 CVE-2023-32861: In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead
In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08059081; Issue ID: ALPS08059081.
nvd
CVE-2023-21209P4MEDIUMCVSS 6.7v13.0vAndroid-132023-06-28
CVE-2023-21209 [MEDIUM] CWE-502 CVE-2023-21209: In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deseria
In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236273
nvd
CVE-2022-26455P4MEDIUMCVSS 6.7v12.02022-09-06
CVE-2022-26455 [MEDIUM] CWE-787 CVE-2022-26455: In gz, there is a possible memory corruption due to incorrect error handling. This could lead to loc
In gz, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177858; Issue ID: ALPS07177858.
nvd
CVE-2022-47341P4MEDIUMCVSS 6.7v10.0v11.02023-02-12
CVE-2022-47341 [MEDIUM] CWE-862 CVE-2022-47341: In engineermode services, there is a missing permission check. This could lead to local escalation o
In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
nvd
CVE-2022-21788P4MEDIUMCVSS 6.7v12.02022-08-01
CVE-2022-21788 [MEDIUM] CVE-2022-21788: In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to l
In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06988728; Issue ID: ALPS06988728.
nvd
CVE-2022-32633P4MEDIUMCVSS 6.7v11.0v12.0+1 more2022-12-05
CVE-2022-32633 [MEDIUM] CWE-269 CVE-2022-32633: In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local
In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441637; Issue ID: ALPS07441637.
nvd
CVE-2023-20744P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20744 [MEDIUM] CWE-416 CVE-2023-20744: In vcu, there is a possible use after free due to a logic error. This could lead to local escalation
In vcu, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519142; Issue ID: ALPS07519200.
nvd
CVE-2023-21171P4MEDIUMCVSS 6.7v13.0vAndroid-132023-06-28
CVE-2023-21171 [MEDIUM] CVE-2023-21171: In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to si
In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to side channel information disclosure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261085213
nvd
CVE-2021-0625P4MEDIUMCVSS 6.7v10.0v11.02021-10-25
CVE-2021-0625 [MEDIUM] CWE-667 CVE-2021-0625: In ccu, there is a possible memory corruption due to improper locking. This could lead to local esca
In ccu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594996; Issue ID: ALPS05594996.
nvd
CVE-2023-20664P4MEDIUMCVSS 6.7v10.0v11.0+2 more2023-04-06
CVE-2023-20664 [MEDIUM] CWE-416 CVE-2023-20664: In gz, there is a possible double free due to a use after free. This could lead to local escalation
In gz, there is a possible double free due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07505952; Issue ID: ALPS07505952.
nvd
CVE-2023-21084P4MEDIUMCVSS 6.7v13.0vAndroid-132023-04-19
CVE-2023-21084 [MEDIUM] CVE-2023-21084: In buildPropFile of filesystem.go, there is a possible insecure hash due to an improperly used crypt
In buildPropFile of filesystem.go, there is a possible insecure hash due to an improperly used crypto. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262892300
nvd
CVE-2022-20016P4MEDIUMCVSS 6.7v10.0v11.02022-01-04
CVE-2022-20016 [MEDIUM] CWE-667 CVE-2022-20016: In vow driver, there is a possible memory corruption due to improper locking. This could lead to loc
In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862986; Issue ID: ALPS05862986.
nvd
CVE-2024-20105P4MEDIUMCVSS 6.7v12.0v13.0+2 more2025-01-06
CVE-2024-20105 [MEDIUM] CWE-787 CVE-2024-20105: In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09062027; Issue ID: MSV-1743.
nvd
CVE-2022-21772P4MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21772 [MEDIUM] CWE-362 CVE-2022-21772: In TEEI driver, there is a possible type confusion due to a race condition. This could lead to local
In TEEI driver, there is a possible type confusion due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493842; Issue ID: ALPS06493842.
nvd
CVE-2022-21775P4MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21775 [MEDIUM] CWE-667 CVE-2022-21775: In sched driver, there is a possible use after free due to improper locking. This could lead to loca
In sched driver, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479032; Issue ID: ALPS06479032.
nvd
CVE-2023-40654P4MEDIUMCVSS 6.7v11.02023-10-08
CVE-2023-40654 [MEDIUM] CWE-862 CVE-2023-40654: In FW-PackageManager, there is a possible missing permission check. This could lead to local escalat
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed
nvd
CVE-2023-40653P4MEDIUMCVSS 6.7v11.02023-10-08
CVE-2023-40653 [MEDIUM] CWE-862 CVE-2023-40653: In FW-PackageManager, there is a possible missing permission check. This could lead to local escalat
In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed
nvd
CVE-2022-20071P4MEDIUMCVSS 6.7v11.0v12.02022-04-11
CVE-2022-20071 [MEDIUM] CWE-295 CVE-2022-20071: In ccu, there is a possible escalation of privilege due to a missing certificate validation. This co
In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06183315; Issue ID: ALPS06183315.
nvd
CVE-2022-26451P4MEDIUMCVSS 6.7v12.02022-09-06
CVE-2022-26451 [MEDIUM] CWE-667 CVE-2022-26451: In ged, there is a possible use after free due to improper locking. This could lead to local escalat
In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202966; Issue ID: ALPS07202966.
nvd