cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 221 of 339
CVE-2022-20290P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20290 [MEDIUM] CVE-2022-20290: In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. Th In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-203549963
nvd
CVE-2023-42710P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42710 [MEDIUM] CWE-862 CVE-2023-42710: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42701P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42701 [MEDIUM] CWE-862 CVE-2023-42701: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42733P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42733 [MEDIUM] CWE-862 CVE-2023-42733: In telephony service, there is a possible missing permission check. This could lead to local informa In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42711P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42711 [MEDIUM] CWE-862 CVE-2023-42711: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42702P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42702 [MEDIUM] CWE-862 CVE-2023-42702: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42734P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42734 [MEDIUM] CWE-862 CVE-2023-42734: In telephony service, there is a possible missing permission check. This could lead to local informa In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42707P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42707 [MEDIUM] CWE-862 CVE-2023-42707: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42706P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42706 [MEDIUM] CWE-862 CVE-2023-42706: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42703P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42703 [MEDIUM] CWE-862 CVE-2023-42703: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42709P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42709 [MEDIUM] CWE-862 CVE-2023-42709: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42732P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42732 [MEDIUM] CWE-862 CVE-2023-42732: In telephony service, there is a possible missing permission check. This could lead to local informa In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42712P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42712 [MEDIUM] CWE-862 CVE-2023-42712: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42713P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42713 [MEDIUM] CWE-862 CVE-2023-42713: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42700P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42700 [MEDIUM] CWE-862 CVE-2023-42700: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42714P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42714 [MEDIUM] CWE-862 CVE-2023-42714: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42708P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42708 [MEDIUM] CWE-862 CVE-2023-42708: In firewall service, there is a possible way to write permission usage records of an app due to a mi In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2025-48642P4MEDIUMCVSS 5.5v14.0v15.0+5 more2026-03-02
CVE-2025-48642 [MEDIUM] CWE-200 CVE-2025-48642: In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21211P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21211 [MEDIUM] CWE-125 CVE-2023-21211: In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262235998
nvd
CVE-2024-49728P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-02
CVE-2024-49728 [MEDIUM] CWE-610 CVE-2024-49728: In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosur In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase