cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 212 of 339
CVE-2025-20694P4MEDIUMCVSS 6.5v13.0v14.0+1 more2025-07-08
CVE-2025-20694 [MEDIUM] CWE-124 CVE-2025-20694: In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to r In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09752821; Issue ID: MSV-3342.
nvd
CVE-2022-20553P4MEDIUMCVSS 6.5v13.0vAndroid-132022-12-16
CVE-2022-20553 [MEDIUM] CWE-1021 CVE-2022-20553: In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check du In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244155265
nvd
CVE-2022-20063P4MEDIUMCVSS 6.5v9.0v10.02022-04-11
CVE-2022-20063 [MEDIUM] CWE-787 CVE-2022-20063: In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID: ALPS06171715.
nvd
CVE-2023-20849P4MEDIUMCVSS 6.5v11.0v12.02023-09-04
CVE-2023-20849 [MEDIUM] CWE-416 CVE-2023-20849: In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.
nvd
CVE-2023-20841P4MEDIUMCVSS 6.5v11.0v12.02023-09-04
CVE-2023-20841 [MEDIUM] CWE-787 CVE-2023-20841: In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326441.
nvd
CVE-2023-20842P4MEDIUMCVSS 6.5v11.0v12.02023-09-04
CVE-2023-20842 [MEDIUM] CWE-787 CVE-2023-20842: In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue ID: ALPS07340477.
nvd
CVE-2023-20850P4MEDIUMCVSS 6.5v11.0v12.02023-09-04
CVE-2023-20850 [MEDIUM] CWE-787 CVE-2023-20850: In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381.
nvd
CVE-2023-20840P4MEDIUMCVSS 6.5v11.0v12.02023-09-04
CVE-2023-20840 [MEDIUM] CWE-125 CVE-2023-20840: In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. T In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID: ALPS07326430.
nvd
CVE-2023-32805P4MEDIUMCVSS 6.5v11.0v12.02023-09-04
CVE-2023-32805 [MEDIUM] CWE-787 CVE-2023-32805: In power, there is a possible out of bounds write due to an insecure default value. This could lead In power, there is a possible out of bounds write due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08102892; Issue ID: ALPS08102892.
nvd
CVE-2022-32643P4MEDIUMCVSS 6.4v12.02023-02-06
CVE-2022-32643 [MEDIUM] CWE-662 CVE-2022-32643: In ccd, there is a possible use after free due to a race condition. This could lead to local escalat In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07341261.
nvd
CVE-2022-32642P4MEDIUMCVSS 6.4v12.02023-02-06
CVE-2022-32642 [MEDIUM] CWE-662 CVE-2022-32642: In ccd, there is a possible memory corruption due to a race condition. This could lead to local esca In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326547; Issue ID: ALPS07326547.
nvd
CVE-2022-32609P4MEDIUMCVSS 6.4v11.0v12.0+1 more2022-11-08
CVE-2022-32609 [MEDIUM] CWE-662 CVE-2022-32609: In vcu, there is a possible use after free due to a race condition. This could lead to local escalat In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203410; Issue ID: ALPS07203410.
nvd
CVE-2022-32610P4MEDIUMCVSS 6.4v11.0v12.0+1 more2022-11-08
CVE-2022-32610 [MEDIUM] CWE-662 CVE-2022-32610: In vcu, there is a possible use after free due to a race condition. This could lead to local escalat In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203476; Issue ID: ALPS07203476.
nvd
CVE-2022-32644P4MEDIUMCVSS 6.4v11.0v12.0+1 more2023-01-03
CVE-2022-32644 [MEDIUM] CWE-662 CVE-2022-32644: In vow, there is a possible use after free due to a race condition. This could lead to local escalat In vow, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494473; Issue ID: ALPS07494473.
nvd
CVE-2022-32648P4MEDIUMCVSS 6.4v11.0v12.02023-01-03
CVE-2022-32648 [MEDIUM] CWE-662 CVE-2022-32648: In disp, there is a possible use after free due to a race condition. This could lead to local escala In disp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535964; Issue ID: ALPS06535964.
nvd
CVE-2019-2189P4MEDIUMCVSS 6.4v10.0vAndroid kernel2019-09-27
CVE-2019-2189 [MEDIUM] CWE-362 CVE-2019-2189: In the Easel driver, there is possible memory corruption due to race conditions. This could lead to In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112312381
nvd
CVE-2019-2188P4MEDIUMCVSS 6.4v10.0vAndroid kernel2019-09-27
CVE-2019-2188 [MEDIUM] CWE-362 CVE-2019-2188: In the Easel driver, there is possible memory corruption due to race conditions. This could lead to In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112309571
nvd
CVE-2020-0126P4MEDIUMCVSS 6.4v10.0vAndroid-102020-06-11
CVE-2020-0126 [MEDIUM] CWE-362 CVE-2020-0126: In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local code execution with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137878930
nvd
CVE-2022-32608P4MEDIUMCVSS 6.4v12.02022-11-08
CVE-2022-32608 [MEDIUM] CWE-367 CVE-2022-32608: In jpeg, there is a possible use after free due to a race condition. This could lead to local escala In jpeg, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388753; Issue ID: ALPS07388753.
nvd
CVE-2022-32613P4MEDIUMCVSS 6.4v11.0v12.0+1 more2022-11-08
CVE-2022-32613 [MEDIUM] CWE-362 CVE-2022-32613: In vcu, there is a possible memory corruption due to a race condition. This could lead to local esca In vcu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07206340; Issue ID: ALPS07206340.
nvd
Google Android vulnerabilities | cvebase