Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 218 of 339
CVE-2019-2198P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-11-13
CVE-2019-2198 [MEDIUM] CWE-89 CVE-2019-2198: In Download Provider, there is a possible SQL injection vulnerability. This could lead to local info
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135270103
nvd
CVE-2024-0030P4MEDIUMCVSS 5.5v11.0v12.0+8 more2024-02-16
CVE-2024-0030 [MEDIUM] CWE-125 CVE-2024-0030: In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incor
In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-25456P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-09-09
CVE-2021-25456 [MEDIUM] CWE-125 CVE-2021-25456: OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attacke
OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.
nvd
CVE-2020-0365P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0365 [MEDIUM] CWE-125 CVE-2020-0365: In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to re
In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137346580
nvd
CVE-2024-47039P4MEDIUMCVSS 5.5v10.0vv102024-12-18
CVE-2024-47039 [MEDIUM] CWE-125 CVE-2024-47039: In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missin
In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-39117P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-39117 [MEDIUM] CWE-862 CVE-2022-39117: In messaging service, there is a missing permission check. This could lead to local information disc
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2024-32893P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-32893 [MEDIUM] CWE-125 CVE-2024-32893: In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper ca
In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20909P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-20909 [MEDIUM] CWE-862 CVE-2023-20909: In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missin
In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-2431
nvd
CVE-2021-25413P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-06-11
CVE-2021-25413 [MEDIUM] CWE-20 CVE-2021-25413: Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege.
nvd
CVE-2023-40133P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-10-27
CVE-2023-40133 [MEDIUM] CVE-2023-40133: In multiple locations of DialogFillUi.java, there is a possible way to view another user's images du
In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21285P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21285 [MEDIUM] CVE-2023-21285: In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due
In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-38689P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38689 [MEDIUM] CWE-200 CVE-2022-38689: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-33902P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-07-12
CVE-2023-33902 [MEDIUM] CWE-862 CVE-2023-33902: In bluetooth service, there is a missing permission check. This could lead to local information disc
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-38688P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38688 [MEDIUM] CWE-200 CVE-2022-38688: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-35668P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-12-04
CVE-2023-35668 [MEDIUM] CVE-2023-35668: In visitUris of Notification.java, there is a possible way to display images from another user due t
In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40101P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-40101 [MEDIUM] CWE-125 CVE-2023-40101: In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds che
In collapse of canonicalize_md.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0177P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0177 [MEDIUM] CWE-862 CVE-2020-0177: In connect() of PanService.java, there is a possible permissions bypass. This could lead to local es
In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connection settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-126206353
nvd
CVE-2022-20496P4MEDIUMCVSS 5.5v12.0v12.1+2 more2022-12-13
CVE-2022-20496 [MEDIUM] CWE-416 CVE-2022-20496: In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due t
In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-245242273
nvd
CVE-2021-25397P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-06-11
CVE-2021-25397 [MEDIUM] CWE-926 CVE-2021-25397: An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
nvd
CVE-2022-20457P4MEDIUMCVSS 5.5v13.0vAndroid-132022-11-08
CVE-2022-20457 [MEDIUM] CWE-20 CVE-2022-20457: In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package ins
In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-243924784
nvd