cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 217 of 339
CVE-2022-20090P4MEDIUMCVSS 6.4v11.0v12.02022-05-03
CVE-2022-20090 [MEDIUM] CWE-362 CVE-2022-20090: In aee driver, there is a possible use after free due to a race condition. This could lead to local In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209197; Issue ID: ALPS06209197.
nvd
CVE-2022-20091P4MEDIUMCVSS 6.4v11.0v12.02022-05-03
CVE-2022-20091 [MEDIUM] CWE-362 CVE-2022-20091: In aee driver, there is a possible use after free due to a race condition. This could lead to local In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06226345.
nvd
CVE-2022-26450P4MEDIUMCVSS 6.4v12.02022-09-06
CVE-2022-26450 [MEDIUM] CWE-362 CVE-2022-26450: In apusys, there is a possible use after free due to a race condition. This could lead to local esca In apusys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07177801; Issue ID: ALPS07177801.
nvd
CVE-2023-20684P4MEDIUMCVSS 6.4v12.0v13.02023-04-06
CVE-2023-20684 [MEDIUM] CWE-362 CVE-2023-20684: In vdec, there is a possible use after free due to a race condition. This could lead to local escala In vdec, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07671069; Issue ID: ALPS07671069.
nvd
CVE-2023-20685P4MEDIUMCVSS 6.4v12.0v13.02023-04-06
CVE-2023-20685 [MEDIUM] CWE-362 CVE-2023-20685: In vdec, there is a possible use after free due to a race condition. This could lead to local escala In vdec, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608575; Issue ID: ALPS07608575.
nvd
CVE-2023-20834P4MEDIUMCVSS 6.4v12.0v13.02023-09-04
CVE-2023-20834 [MEDIUM] CWE-362 CVE-2023-20834: In pda, there is a possible use after free due to a race condition. This could lead to local escalat In pda, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608514; Issue ID: ALPS07608514.
nvd
CVE-2024-20048P4MEDIUMCVSS 6.2v12.0v13.02024-04-01
CVE-2024-20048 [MEDIUM] CWE-248 CVE-2024-20048: In flashc, there is a possible information disclosure due to an uncaught exception. This could lead In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.
nvd
CVE-2018-9378P4MEDIUMCVSS 6.2v6.0v6.0.1+6 more2025-01-28
CVE-2018-9378 [MEDIUM] CWE-908 CVE-2018-9378: In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disc In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20136P4MEDIUMCVSS 6.2v12.0v13.0+2 more2024-12-02
CVE-2024-20136 [MEDIUM] CWE-125 CVE-2024-20136: In da, there is a possible out of bounds read due to a missing bounds check. This could lead to loca In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID: MSV-1821.
nvd
CVE-2024-40664P4MEDIUMCVSS 6.2v13.0v14.0+2 more2025-09-04
CVE-2024-40664 [MEDIUM] CWE-400 CVE-2024-40664: In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an ena In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-2423P4MEDIUMCVSS 6.1v4.0v4.0.1+20 more2016-04-18
CVE-2016-2423 [MEDIUM] CWE-264 CVE-2016-2423: server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka int
nvd
CVE-2017-11063P4MEDIUMCVSS 5.9v8.02017-10-10
CVE-2017-11063 [MEDIUM] CWE-476 CVE-2017-11063: In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Li In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, as a result of a race condition between two userspace processes that interact with the driver concurrently, a null pointer dereference can potentially occur.
nvd
CVE-2023-52345P4MEDIUMCVSS 6.0v12.0v13.0+1 more2024-04-08
CVE-2023-52345 [MEDIUM] CWE-922 CVE-2023-52345: In modem driver, there is a possible system crash due to improper input validation. This could lead In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed
nvd
CVE-2024-29747P4MEDIUMCVSS 5.9vAndroid kernel2024-04-05
CVE-2024-29747 [MEDIUM] CWE-125 CVE-2024-29747: In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0499P4MEDIUMCVSS 4.3v11.0vAndroid-112020-12-15
CVE-2020-0499 [MEDIUM] CWE-125 CVE-2020-0499: In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070
nvd
CVE-2020-0383P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-09-17
CVE-2020-0383 [MEDIUM] CWE-787 CVE-2020-0383: In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. T In Parse_ins of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure in the media extractor process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0A
nvd
CVE-2017-13317P4MEDIUMCVSS 5.7v8.1vAndroid Kernel2025-01-28
CVE-2017-13317 [MEDIUM] CWE-125 CVE-2017-13317: In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due t In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2017-13318P4MEDIUMCVSS 5.7v8.1vAndroid Kernel2025-01-28
CVE-2017-13318 [MEDIUM] CWE-125 CVE-2017-13318: In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an i In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-0561P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0561 [MEDIUM] CWE-787 CVE-2021-0561: In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write d In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683
nvd
CVE-2016-3918P4MEDIUMCVSS 5.5v4.0v4.0.1+21 more2016-10-10
CVE-2016-3918 [MEDIUM] CWE-200 CVE-2016-3918: email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not ensure that certain values are integers, which allows attackers to read arbitrary attachments via a crafted application that provides a pathname value, aka internal bug 30745
nvd
Google Android vulnerabilities | cvebase