cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 222 of 339
CVE-2025-0082P4MEDIUMCVSS 5.5v12.0v12.1+8 more2025-08-26
CVE-2025-0082 [MEDIUM] CWE-610 CVE-2025-0082: In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to rev In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-40085P4MEDIUMCVSS 5.5v12.0v12.1+4 more2024-02-16
CVE-2023-40085 [MEDIUM] CWE-125 CVE-2023-40085: In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a miss In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21377P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21377 [MEDIUM] CVE-2023-21377: In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could le In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40123P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-10-27
CVE-2023-40123 [MEDIUM] CVE-2023-40123: In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security bounda In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-33901P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-07-12
CVE-2023-33901 [MEDIUM] CWE-862 CVE-2023-33901: In bluetooth service, there is a missing permission check. This could lead to local information disc In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47477P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47477 [MEDIUM] CWE-862 CVE-2022-47477: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47473P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47473 [MEDIUM] CWE-862 CVE-2022-47473: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47472P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47472 [MEDIUM] CWE-862 CVE-2022-47472: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47476P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47476 [MEDIUM] CWE-862 CVE-2022-47476: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47475P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47475 [MEDIUM] CWE-862 CVE-2022-47475: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47478P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47478 [MEDIUM] CWE-862 CVE-2022-47478: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47471P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47471 [MEDIUM] CWE-862 CVE-2022-47471: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47479P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47479 [MEDIUM] CWE-862 CVE-2022-47479: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2022-47474P4MEDIUMCVSS 5.5v10.0v11.02023-03-10
CVE-2022-47474 [MEDIUM] CWE-862 CVE-2022-47474: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2024-27232P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-27232 [MEDIUM] CWE-476 CVE-2024-27232: In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. Th In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29744P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-29744 [MEDIUM] CWE-125 CVE-2024-29744: In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. T In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29751P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-29751 [MEDIUM] CWE-476 CVE-2024-29751: In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null chec In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27237P4MEDIUMCVSS 5.5v132024-03-11
CVE-2024-27237 [MEDIUM] CWE-131 CVE-2024-27237: In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic erro In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21385P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21385 [MEDIUM] CWE-787 CVE-2023-21385: In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21249P4MEDIUMCVSS 5.5v13.0v132023-07-13
CVE-2023-21249 [MEDIUM] CWE-281 CVE-2023-21249: In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase