cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 211 of 339
CVE-2022-21770P4MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21770 [MEDIUM] CWE-59 CVE-2022-21770: In sound driver, there is a possible information disclosure due to symlink following. This could lea In sound driver, there is a possible information disclosure due to symlink following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558663; Issue ID: ALPS06558663.
nvd
CVE-2022-20065P4MEDIUMCVSS 6.7v10.0v11.0+1 more2022-04-11
CVE-2022-20065 [MEDIUM] CWE-125 CVE-2022-20065: In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to lo In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108658; Issue ID: ALPS06108658.
nvd
CVE-2023-20656P4MEDIUMCVSS 6.7v10.0v11.0+2 more2023-04-06
CVE-2023-20656 [MEDIUM] CWE-787 CVE-2023-20656: In geniezone, there is a possible out of bounds write due to a logic error. This could lead to local In geniezone, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07571494; Issue ID: ALPS07571494.
nvd
CVE-2023-32884P4MEDIUMCVSS 6.7v12.0v13.02024-01-02
CVE-2023-32884 [MEDIUM] CWE-119 CVE-2023-32884: In netdagent, there is a possible information disclosure due to an incorrect bounds check. This coul In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944011; Issue ID: ALPS07944011.
nvd
CVE-2022-21773P4MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21773 [MEDIUM] CWE-362 CVE-2022-21773: In TEEI driver, there is a possible use after free due to a race condition. This could lead to local In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641388; Issue ID: ALPS06641388.
nvd
CVE-2022-21774P4MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21774 [MEDIUM] CWE-362 CVE-2022-21774: In TEEI driver, there is a possible use after free due to a race condition. This could lead to local In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641447; Issue ID: ALPS06641447.
nvd
CVE-2022-21771P4MEDIUMCVSS 6.7v11.0v12.02022-07-06
CVE-2022-21771 [MEDIUM] CWE-362 CVE-2022-21771: In GED driver, there is a possible use after free due to a race condition. This could lead to local In GED driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641585; Issue ID: ALPS06641585.
nvd
CVE-2022-20060P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-03-10
CVE-2022-20060 [MEDIUM] CWE-306 CVE-2022-20060: In preloader (usb), there is a possible permission bypass due to a missing proper image authenticati In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06137462.
nvd
CVE-2024-20144P4MEDIUMCVSS 6.6v13.0v14.0+1 more2025-01-06
CVE-2024-20144 [MEDIUM] CWE-787 CVE-2024-20144: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2041.
nvd
CVE-2024-20145P4MEDIUMCVSS 6.6v14.0v15.02025-01-06
CVE-2024-20145 [MEDIUM] CWE-787 CVE-2024-20145: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040.
nvd
CVE-2024-20143P4MEDIUMCVSS 6.6v12.0v13.0+2 more2025-01-06
CVE-2024-20143 [MEDIUM] CWE-787 CVE-2024-20143: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2069.
nvd
CVE-2025-20642P4MEDIUMCVSS 6.6v12.0v13.0+2 more2025-02-03
CVE-2025-20642 [MEDIUM] CWE-787 CVE-2025-20642: In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to loc In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2057.
nvd
CVE-2024-20141P4MEDIUMCVSS 6.6v12.0v13.0+2 more2025-02-03
CVE-2024-20141 [MEDIUM] CWE-123 CVE-2024-20141: In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291402; Issue ID: MSV-2073.
nvd
CVE-2025-20639P4MEDIUMCVSS 6.6v12.0v13.0+2 more2025-02-03
CVE-2025-20639 [MEDIUM] CWE-787 CVE-2025-20639: In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to loc In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2060.
nvd
CVE-2024-20142P4MEDIUMCVSS 6.6v12.0v13.0+2 more2025-02-03
CVE-2024-20142 [MEDIUM] CWE-787 CVE-2024-20142: In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291406; Issue ID: MSV-2070.
nvd
CVE-2025-20635P4MEDIUMCVSS 6.6v12.0v13.0+2 more2025-02-03
CVE-2025-20635 [MEDIUM] CWE-787 CVE-2025-20635: In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09403752; Issue ID: MSV-2434.
nvd
CVE-2025-20641P4MEDIUMCVSS 6.6v12.0v13.0+2 more2025-02-03
CVE-2025-20641 [MEDIUM] CWE-787 CVE-2025-20641: In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to loc In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2058.
nvd
CVE-2018-9593P4MEDIUMCVSS 6.5v7.0v7.1.1+4 more2019-02-11
CVE-2018-9593 [MEDIUM] CWE-125 CVE-2018-9593: In llcp_dlc_proc_i_pdu of llcp_dlc.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, And In llcp_dlc_proc_i_pdu of llcp_dlc.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation. An
nvd
CVE-2022-20022P4MEDIUMCVSS 6.5v10.0v11.02022-01-04
CVE-2022-20022 [MEDIUM] CVE-2022-20022: In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a con In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from a host with the same BD address as the currently connected BT host. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06
nvd
CVE-2025-20695P4MEDIUMCVSS 6.5v13.0v14.0+1 more2025-07-08
CVE-2025-20695 [MEDIUM] CWE-124 CVE-2025-20695: In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to r In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317.
nvd
Google Android vulnerabilities | cvebase