cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 216 of 339
CVE-2022-26091P4MEDIUMCVSS 6.8v10.0v11.0+1 more2022-04-11
CVE-2022-26091 [MEDIUM] CWE-284 CVE-2022-26091: Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that phy Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.
nvd
CVE-2021-25481P4MEDIUMCVSS 6.7v8.1v9.0+2 more2021-10-06
CVE-2021-25481 [MEDIUM] CWE-754 CVE-2021-25481: An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.
nvd
CVE-2023-20732P4MEDIUMCVSS 6.7v12.0v13.02023-06-06
CVE-2023-20732 [MEDIUM] CWE-787 CVE-2023-20732: In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to lo In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573480; Issue ID: ALPS07573480.
nvd
CVE-2016-2411P4MEDIUMCVSS 6.5v6.0v6.0.12016-04-18
CVE-2016-2411 [MEDIUM] CWE-20 CVE-2016-2411: A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages root access, aka internal bug 26866053.
nvd
CVE-2022-20069P4MEDIUMCVSS 6.6v10.0v11.0+1 more2022-04-11
CVE-2022-20069 [MEDIUM] CWE-190 CVE-2022-20069: In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could l In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160425; Issue ID: ALPS06160425.
nvd
CVE-2017-13235P4MEDIUMCVSS 6.5v5.1.1v6.0+6 more2018-02-12
CVE-2017-13235 [MEDIUM] CWE-476 CVE-2017-13235: A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68342866.
nvd
CVE-2020-0196P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0196 [MEDIUM] CWE-20 CVE-2020-0196: In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible ab In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-
nvd
CVE-2022-20023P4MEDIUMCVSS 6.5v10.0v11.02022-01-04
CVE-2022-20023 [MEDIUM] CWE-772 CVE-2022-20023: In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_r In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198608; Issue ID: ALPS06198608.
nvd
CVE-2022-20253P4MEDIUMCVSS 6.5v13.0vAndroid-132022-08-12
CVE-2022-20253 [MEDIUM] CWE-755 CVE-2022-20253: In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to r In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to remote denial of service in Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224545125
nvd
CVE-2022-20334P4MEDIUMCVSS 6.5v13.0vAndroid-132022-08-12
CVE-2022-20334 [MEDIUM] CWE-476 CVE-2022-20334: In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lea In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-178800552
nvd
CVE-2022-20333P4MEDIUMCVSS 6.5v13.0vAndroid-132022-08-12
CVE-2022-20333 [MEDIUM] CWE-476 CVE-2022-20333: In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denia In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-179161657
nvd
CVE-2019-9238P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9238 [MEDIUM] CWE-787 CVE-2019-9238: In the NFC stack, there is a possible out of bounds write due to a missing bounds check. This could In the NFC stack, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121267042
nvd
CVE-2022-20052P4MEDIUMCVSS 6.5v11.0v12.02022-04-11
CVE-2022-20052 [MEDIUM] CWE-416 CVE-2022-20052: In mdp, there is a possible memory corruption due to a use after free. This could lead to local esca In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS05836642; Issue ID: ALPS05836642.
nvd
CVE-2024-43763P4MEDIUMCVSS 6.5v12.0v12.1+8 more2025-01-21
CVE-2024-43763 [MEDIUM] CWE-400 CVE-2024-43763: In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20139P4MEDIUMCVSS 6.5v13.0v14.0+1 more2024-12-02
CVE-2024-20139 [MEDIUM] CWE-617 CVE-2024-20139: In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.
nvd
CVE-2023-20848P4MEDIUMCVSS 6.5v11.0v12.02023-09-04
CVE-2023-20848 [MEDIUM] CWE-125 CVE-2023-20848: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433.
nvd
CVE-2023-20800P4MEDIUMCVSS 6.5v12.0v13.02023-08-07
CVE-2023-20800 [MEDIUM] CWE-863 CVE-2023-20800: In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local esca In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420955.
nvd
CVE-2023-20611P4MEDIUMCVSS 6.4v12.0v13.02023-02-06
CVE-2023-20611 [MEDIUM] CWE-662 CVE-2023-20611: In gpu, there is a possible use after free due to a race condition. This could lead to local escalat In gpu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588678; Issue ID: ALPS07588678.
nvd
CVE-2023-20608P4MEDIUMCVSS 6.4v11.0v12.0+1 more2023-02-06
CVE-2023-20608 [MEDIUM] CWE-416 CVE-2023-20608: In display drm, there is a possible use after free due to a race condition. This could lead to local In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599.
nvd
CVE-2022-21776P4MEDIUMCVSS 6.4v11.0v12.02022-07-06
CVE-2022-21776 [MEDIUM] CWE-362 CVE-2022-21776: In MDP, there is a possible use after free due to a race condition. This could lead to local escalat In MDP, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545450; Issue ID: ALPS06545450.
nvd
Google Android vulnerabilities | cvebase