cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 230 of 339
CVE-2011-0680P4MEDIUMCVSS 5.0≤ 2.2.1v1.5+4 more2011-01-31
CVE-2011-0680 [MEDIUM] CVE-2011-0680: data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service.
nvd
CVE-2017-10996P4MEDIUMCVSS 5.5≤ 8.02017-09-21
CVE-2017-10996 [MEDIUM] CWE-200 CVE-2017-10996: In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory violation/out of bounds access.
nvd
CVE-2019-2196P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-11-13
CVE-2019-2196 [MEDIUM] CWE-89 CVE-2019-2196: In Download Provider, there is possible SQL injection. This could lead to local information disclosu In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269143
nvd
CVE-2016-8467P4MEDIUMCVSS 5.5≤ 7.1.02017-01-13
CVE-2016-8467 [MEDIUM] CWE-264 CVE-2016-8467: An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute a An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completely permanent or requiring re-flashing the entire operating system). Product: Android. Versions: N/A. A
nvd
CVE-2018-9499P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9499 [MEDIUM] CWE-908 CVE-2018-9499: In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local information disclosure from the DRM server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android
nvd
CVE-2021-0394P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-03-10
CVE-2021-0394 [MEDIUM] CWE-125 CVE-2021-0394: In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read du In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID:
nvd
CVE-2020-0344P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0344 [MEDIUM] CWE-89 CVE-2020-0344: In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to lo In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140729887
nvd
CVE-2020-0352P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0352 [MEDIUM] CWE-89 CVE-2020-0352: In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to lo In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132074310
nvd
CVE-2022-20518P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20518 [MEDIUM] CWE-89 CVE-2022-20518: In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injectio In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203
nvd
CVE-2022-20517P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20517 [MEDIUM] CWE-89 CVE-2022-20517: In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224769956
nvd
CVE-2022-20513P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20513 [MEDIUM] CWE-125 CVE-2022-20513: In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds c In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244569759
nvd
CVE-2023-21118P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21118 [MEDIUM] CWE-125 CVE-2023-21118: In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overf In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004
nvd
CVE-2023-21238P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-07-13
CVE-2023-21238 [MEDIUM] CWE-384 CVE-2023-21238: In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-2136P4MEDIUMCVSS 5.5v7.0v7.1.1+5 more2019-08-20
CVE-2019-2136 [MEDIUM] CWE-20 CVE-2019-2136: In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper inpu In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 And
nvd
CVE-2020-0294P4MEDIUMCVSS 5.5v11.0vAndroid-10 Android-8.0 Android-8.1 Android-92020-09-18
CVE-2020-0294 [MEDIUM] CWE-276 CVE-2020-0294: In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypa In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID:
nvd
CVE-2023-21288P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21288 [MEDIUM] CWE-862 CVE-2023-21288: In visitUris of Notification.java, there is a possible way to reveal images across users due to a mi In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0061P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-10
CVE-2020-0061 [MEDIUM] CVE-2020-0061: In Pixel Recorder, there is a possible permissions bypass allowing arbitrary apps to record audio. T In Pixel Recorder, there is a possible permissions bypass allowing arbitrary apps to record audio. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145504977
nvd
CVE-2022-20523P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20523 [MEDIUM] CWE-125 CVE-2022-20523: In IncFs_GetFilledRangesStartingFrom of incfs.cpp, there is a possible out of bounds read due to a m In IncFs_GetFilledRangesStartingFrom of incfs.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228222508
nvd
CVE-2018-9340P4MEDIUMCVSS 5.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9340 [MEDIUM] CWE-125 CVE-2018-9340: In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.
nvd
CVE-2022-42535P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-42535 [MEDIUM] CWE-89 CVE-2022-42535: In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL inject In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770183
nvd
Google Android vulnerabilities | cvebase