cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 209 of 339
CVE-2020-0268P4MEDIUMCVSS 6.4v11.0vAndroid-112020-09-18
CVE-2020-0268 [MEDIUM] CWE-362 CVE-2020-0268: In NFC, there is a possible use-after-free due to a race condition. This could lead to local escalat In NFC, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148294643
nvd
CVE-2021-0387P4MEDIUMCVSS 6.4v11.0vAndroid-112021-03-10
CVE-2021-0387 [MEDIUM] CWE-362 CVE-2021-0387: In FindQuotaDeviceForUuid of QuotaUtils.cpp, there is a possible use-after-free due to a race condit In FindQuotaDeviceForUuid of QuotaUtils.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169421939
nvd
CVE-2021-0401P4MEDIUMCVSS 6.4v10.0v11.0+1 more2021-02-26
CVE-2021-0401 [MEDIUM] CWE-362 CVE-2021-0401: In vow, there is a possible memory corruption due to a race condition. This could lead to local esca In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05418265.
nvd
CVE-2021-0366P4MEDIUMCVSS 6.4v10.0v11.0+1 more2021-02-26
CVE-2021-0366 [MEDIUM] CWE-362 CVE-2021-0366: In vpu, there is a possible memory corruption due to a race condition. This could lead to local esca In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05371580; Issue ID: ALPS05379093.
nvd
CVE-2021-0367P4MEDIUMCVSS 6.4v10.0v11.0+1 more2021-02-26
CVE-2021-0367 [MEDIUM] CWE-362 CVE-2021-0367: In vpu, there is a possible memory corruption due to a race condition. This could lead to local esca In vpu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05371580; Issue ID: ALPS05379085.
nvd
CVE-2023-20610P4MEDIUMCVSS 6.4v11.0v12.0+1 more2023-02-06
CVE-2023-20610 [MEDIUM] CWE-662 CVE-2023-20610: In display drm, there is a possible memory corruption due to a race condition. This could lead to lo In display drm, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363469; Issue ID: ALPS07363469.
nvd
CVE-2023-20607P4MEDIUMCVSS 6.4v11.0v12.02023-02-06
CVE-2023-20607 [MEDIUM] CWE-662 CVE-2023-20607: In ccu, there is a possible memory corruption due to a race condition. This could lead to local esca In ccu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07512839; Issue ID: ALPS07512839.
nvd
CVE-2021-0564P4MEDIUMCVSS 6.4v11.0vAndroid-112021-06-22
CVE-2021-0564 [MEDIUM] CWE-362 CVE-2021-0564: In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This cou In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176495665
nvd
CVE-2023-20771P4MEDIUMCVSS 6.4v12.02023-07-04
CVE-2023-20771 [MEDIUM] CWE-362 CVE-2023-20771: In display, there is a possible memory corruption due to a race condition. This could lead to local In display, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671046; Issue ID: ALPS07671046.
nvd
CVE-2023-48420P4MEDIUMCVSS 6.4vAndroid kernel2023-12-08
CVE-2023-48420 [MEDIUM] CWE-362 CVE-2023-48420: there is a possible use after free due to a race condition. This could lead to local escalation of p there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20256P4MEDIUMCVSS 6.4v13.0vAndroid-132022-08-12
CVE-2022-20256 [MEDIUM] CWE-362 CVE-2022-20256: In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead t In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222572821
nvd
CVE-2023-20736P4MEDIUMCVSS 6.4v12.0v13.02023-06-06
CVE-2023-20736 [MEDIUM] CWE-362 CVE-2023-20736: In vcu, there is a possible out of bounds write due to a race condition. This could lead to local es In vcu, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645189.
nvd
CVE-2023-20623P4MEDIUMCVSS 6.4v10.0v11.0+1 more2023-03-07
CVE-2023-20623 [MEDIUM] CWE-367 CVE-2023-20623: In ion, there is a possible escalation of privilege due to improper locking. This could lead to loca In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue ID: ALPS07559778.
nvd
CVE-2023-20785P4MEDIUMCVSS 6.4v12.0v13.02023-08-07
CVE-2023-20785 [MEDIUM] CWE-367 CVE-2023-20785: In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628524; Issue ID: ALPS07628524.
nvd
CVE-2023-20827P4MEDIUMCVSS 6.4v12.0v13.02023-09-04
CVE-2023-20827 [MEDIUM] CWE-362 CVE-2023-20827: In ims service, there is a possible memory corruption due to a race condition. This could lead to lo In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937105; Issue ID: ALPS07937105.
nvd
CVE-2021-25490P4MEDIUMCVSS 6.0v9.0v10.0+1 more2021-10-06
CVE-2021-25490 [MEDIUM] CWE-287 CVE-2021-25490: A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger I A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.
nvd
CVE-2016-10398P4MEDIUMCVSS 6.2v6.02017-07-17
CVE-2016-10398 [MEDIUM] CWE-264 CVE-2016-10398: Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay previously captured responses and use the TEE without authenticating. All apps using authentication-
nvd
CVE-2026-0012P4MEDIUMCVSS 6.2v14.0v15.0+4 more2026-03-02
CVE-2026-0012 [MEDIUM] CWE-284 CVE-2026-0012: In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48527P4MEDIUMCVSS 6.2v13.0v14.0+6 more2025-09-04
CVE-2025-48527 [MEDIUM] CWE-200 CVE-2025-48527: In multiple locations, there is a possible way to leak hidden work profile notifications due to a lo In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29754P4MEDIUMCVSS 6.2vAndroid kernel2024-04-05
CVE-2024-29754 [MEDIUM] CWE-125 CVE-2024-29754: In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This cou In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase