Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 223 of 339
CVE-2023-21308P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21308 [MEDIUM] CWE-125 CVE-2023-21308: In Composer, there is a possible out of bounds read due to a missing bounds check. This could lead t
In Composer, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20722P4MEDIUMCVSS 5.5v14.0v15.02025-10-14
CVE-2025-20722 [MEDIUM] CWE-190 CVE-2025-20722: In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead t
In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID: MSV-3798.
nvd
CVE-2017-13227P4MEDIUMCVSS 5.5v8.0v8.12024-11-14
CVE-2017-13227 [MEDIUM] CVE-2017-13227: In the autofill service, the package name that is provided by the app process is trusted inappropria
In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29750P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-29750 [MEDIUM] CWE-125 CVE-2024-29750: In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check.
In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29782P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-29782 [MEDIUM] CWE-125 CVE-2024-29782: In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bound
In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29738P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-29738 [MEDIUM] CWE-125 CVE-2024-29738: In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead t
In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29739P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-29739 [MEDIUM] CWE-125 CVE-2024-29739: In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check.
In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29742P4MEDIUMCVSS 5.5vAndroid kernel2024-04-05
CVE-2024-29742 [MEDIUM] CWE-125 CVE-2024-29742: In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bound
In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27218P4MEDIUMCVSS 5.5v132024-03-11
CVE-2024-27218 [MEDIUM] CWE-125 CVE-2024-27218: In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This
In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-30921P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30921 [MEDIUM] CWE-862 CVE-2023-30921: In messaging service, there is a missing permission check. This could lead to local information disc
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-30938P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30938 [MEDIUM] CWE-862 CVE-2023-30938: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-30932P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30932 [MEDIUM] CWE-862 CVE-2023-30932: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-32788P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-32788 [MEDIUM] CWE-862 CVE-2023-32788: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-30940P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30940 [MEDIUM] CWE-862 CVE-2023-30940: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-30933P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30933 [MEDIUM] CWE-862 CVE-2023-30933: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-30923P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30923 [MEDIUM] CWE-862 CVE-2023-30923: In messaging service, there is a missing permission check. This could lead to local information disc
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-30913P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30913 [MEDIUM] CWE-862 CVE-2023-30913: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-32789P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-32789 [MEDIUM] CWE-862 CVE-2023-32789: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-30931P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30931 [MEDIUM] CWE-862 CVE-2023-30931: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-33881P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-33881 [MEDIUM] CWE-862 CVE-2023-33881: In telephony service, there is a missing permission check. This could lead to local information disc
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd