Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 214 of 483
CVE-2022-23432MEDIUMCVSS 6.7v10.0v11.0+1 more2022-02-11
CVE-2022-23432 [MEDIUM] CWE-20 CVE-2022-23432: An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 a
An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2022-23426MEDIUMCVSS 6.0v10.0v11.02022-02-11
CVE-2022-23426 [MEDIUM] CWE-94 CVE-2022-23426: A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allow
A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.
nvd
CVE-2022-23431MEDIUMCVSS 6.7v10.0v11.0+1 more2022-02-11
CVE-2022-23431 [MEDIUM] CWE-120 CVE-2022-23431: An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory writ
An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2022-24001MEDIUMCVSS 4.6v12.02022-02-11
CVE-2022-24001 [MEDIUM] CWE-200 CVE-2022-24001: Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.
nvd
CVE-2021-0524MEDIUMCVSS 5.5v12.0vAndroid-122022-02-11
CVE-2021-0524 [MEDIUM] CWE-203 CVE-2021-0524: In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android I
nvd
CVE-2022-23999LOWCVSS 3.3v10.0v11.0+1 more2022-02-11
CVE-2022-23999 [LOW] CWE-20 CVE-2022-23999: PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local at
PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
nvd
CVE-2022-24000LOWCVSS 3.3v10.0v11.0+1 more2022-02-11
CVE-2022-24000 [LOW] CWE-20 CVE-2022-24000: PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 a
PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
nvd
CVE-2022-20040HIGHCVSS 7.8v11.0v12.02022-02-09
CVE-2022-20040 [HIGH] CWE-787 CVE-2022-20040: In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer over
In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219150; Issue ID: ALPS06219150.
nvd
CVE-2022-20026HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20026 [HIGH] CWE-787 CVE-2022-20026: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126827; Issue ID: ALPS06126827.
nvdandroid
CVE-2022-20027HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20027 [HIGH] CWE-787 CVE-2022-20027: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126826; Issue ID: ALPS06126826.
nvdandroid
CVE-2022-20045HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20045 [HIGH] CWE-416 CVE-2022-20045: In Bluetooth, there is a possible service crash due to a use after free. This could lead to local es
In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID: ALPS06126820.
nvd
CVE-2022-20043HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20043 [HIGH] CWE-862 CVE-2022-20043: In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This co
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06148177; Issue ID: ALPS06148177.
nvd
CVE-2022-20024HIGHCVSS 7.8v11.0v12.02022-02-09
CVE-2022-20024 [HIGH] CWE-862 CVE-2022-20024: In system service, there is a possible permission bypass due to a missing permission check. This cou
In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219064; Issue ID: ALPS06219064.
nvdandroid
CVE-2022-20028HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20028 [HIGH] CWE-787 CVE-2022-20028: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198663; Issue ID: ALPS06198663.
nvdandroid
CVE-2022-20031HIGHCVSS 7.8v10.0v11.02022-02-09
CVE-2022-20031 [HIGH] CWE-416 CVE-2022-20031: In fb driver, there is a possible memory corruption due to a use after free. This could lead to loca
In fb driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05850708; Issue ID: ALPS05850708.
nvd
CVE-2022-20025HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20025 [HIGH] CWE-787 CVE-2022-20025: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126832; Issue ID: ALPS06126832.
nvdandroid
CVE-2022-20044HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20044 [HIGH] CWE-416 CVE-2022-20044: In Bluetooth, there is a possible service crash due to a use after free. This could lead to local es
In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID: ALPS06126814.
nvd
CVE-2022-20041HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20041 [HIGH] CWE-862 CVE-2022-20041: In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This co
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108596; Issue ID: ALPS06108596.
nvd
CVE-2022-20036MEDIUMCVSS 5.5v10.0v11.02022-02-09
CVE-2022-20036 [MEDIUM] CWE-20 CVE-2022-20036: In ion driver, there is a possible information disclosure due to an incorrect bounds check. This cou
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID: ALPS06171689.
nvd
CVE-2022-20033MEDIUMCVSS 4.4v11.0v12.02022-02-09
CVE-2022-20033 [MEDIUM] CWE-125 CVE-2022-20033: In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This coul
In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973; Issue ID: ALPS05862973.
nvd