Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 210 of 483
CVE-2021-39701HIGHCVSS 7.8v11.0v12.0+1 more2022-03-16
CVE-2021-39701 [HIGH] CWE-20 CVE-2021-39701: In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersi
nvdandroid
CVE-2021-0957HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-0957 [HIGH] CVE-2021-0957: In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to b In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset Protections. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-193149550
nvdandroid
CVE-2021-39692HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39692 [HIGH] CWE-1021 CVE-2021-39692: In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing u In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-
nvdandroid
CVE-2021-39706HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39706 [HIGH] CWE-862 CVE-2021-39706: In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials sto In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-
nvdandroid
CVE-2021-39707HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39707 [HIGH] CWE-610 CVE-2021-39707: In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A
nvdandroid
CVE-2021-39694HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39694 [HIGH] CWE-276 CVE-2021-39694: In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-202312327
nvdandroid
CVE-2021-39695HIGHCVSS 7.8v11.0vAndroid-112022-03-16
CVE-2021-39695 [HIGH] CWE-281 CVE-2021-39695: In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-209607944
nvdandroid
CVE-2021-39704HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39704 [HIGH] CWE-281 CVE-2021-39704: In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android
nvdandroid
CVE-2021-39703HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39703 [HIGH] CWE-610 CVE-2021-39703: In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a c In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-207057578
nvdandroid
CVE-2021-39693HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39693 [HIGH] CWE-119 CVE-2021-39693: In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a vis In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208662370
nvdandroid
CVE-2021-39702HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39702 [HIGH] CWE-1021 CVE-2021-39702: In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to insta In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID
nvdandroid
CVE-2021-39690MEDIUMCVSS 5.5v12.0vAndroid-122022-03-16
CVE-2021-39690 [MEDIUM] CWE-1284 CVE-2021-39690: In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-204316511
nvdandroid
CVE-2021-39624MEDIUMCVSS 5.5v10.0v11.0+3 more2022-03-16
CVE-2021-39624 [MEDIUM] CVE-2021-39624: In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-67862680
nvdandroid
CVE-2021-39667MEDIUMCVSS 6.5v10.0v11.0+2 more2022-03-16
CVE-2021-39667 [MEDIUM] CWE-787 CVE-2021-39667: In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-205702093
nvdandroid
CVE-2021-39689MEDIUMCVSS 6.7v12.0vAndroid-122022-03-16
CVE-2021-39689 [MEDIUM] CWE-345 CVE-2021-39689: In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-206090748
nvdandroid
CVE-2022-25818CRITICALCVSS 9.8v12.02022-03-10
CVE-2022-25818 [CRITICAL] CWE-20 CVE-2022-25818: Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.
nvd
CVE-2022-20048HIGHCVSS 7.8v10.0v11.0+1 more2022-03-10
CVE-2022-20048 [HIGH] CWE-787 CVE-2022-20048: In video decoder, there is a possible out of bounds write due to a missing bounds check. This could In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917502; Issue ID: ALPS05917502.
nvdandroid
CVE-2022-20053HIGHCVSS 7.8v9.0v10.0+2 more2022-03-10
CVE-2022-20053 [HIGH] CWE-862 CVE-2022-20053: In ims service, there is a possible escalation of privilege due to a missing permission check. This In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219097; Issue ID: ALPS06219097.
nvdandroid
CVE-2022-20047HIGHCVSS 7.8v10.0v11.0+1 more2022-03-10
CVE-2022-20047 [HIGH] CWE-787 CVE-2022-20047: In video decoder, there is a possible out of bounds write due to a missing bounds check. This could In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917489; Issue ID: ALPS05917489.
nvdandroid
CVE-2022-24928HIGHCVSS 7.8v11.02022-03-10
CVE-2022-24928 [HIGH] CWE-815 CVE-2022-24928: Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.
nvd