Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 231 of 339
CVE-2020-0448P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-11-10
CVE-2020-0448 [MEDIUM] CWE-862 CVE-2020-0448: In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracki
In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to track an account across devices, with no additional execution privileges needed. User interaction is not needed fo
nvd
CVE-2023-40083P4MEDIUMCVSS 5.5v12.0v12.1+6 more2023-12-04
CVE-2023-40083 [MEDIUM] CWE-125 CVE-2023-40083: In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check.
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40073P4MEDIUMCVSS 5.5v11.0v12.0+8 more2023-12-04
CVE-2023-40073 [MEDIUM] CVE-2023-40073: In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy.
In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0495P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0495 [MEDIUM] CWE-190 CVE-2020-0495: In decode_Huffman of JBig2_SddProc.cpp, there is a possible out of bounds write due to an integer ov
In decode_Huffman of JBig2_SddProc.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155473137
nvd
CVE-2021-0484P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-06-11
CVE-2021-0484 [MEDIUM] CWE-909 CVE-2021-0484: In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a miss
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-17372076
nvd
CVE-2023-40093P4MEDIUMCVSS 5.5v11.0v12.0+8 more2024-02-16
CVE-2023-40093 [MEDIUM] CWE-922 CVE-2023-40093: In multiple files, there is a possible way that trimmed content could be included in PDF output due
In multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-45781P4MEDIUMCVSS 5.5v12.0v12.1+6 more2023-12-04
CVE-2023-45781 [MEDIUM] CWE-125 CVE-2023-45781: In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check.
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20471P4MEDIUMCVSS 5.5v11.0v12.0+3 more2022-12-13
CVE-2022-20471 [MEDIUM] CWE-125 CVE-2022-20471: In SendIncDecRestoreCmdPart2 of NxpMfcReader.cc, there is a possible out of bounds read due to a mis
In SendIncDecRestoreCmdPart2 of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-2381
nvd
CVE-2022-32602P4MEDIUMCVSS 5.5v11.0v12.02022-11-08
CVE-2022-32602 [MEDIUM] CWE-125 CVE-2022-32602: In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388790; Issue ID: ALPS07388790.
nvd
CVE-2021-0400P4MEDIUMCVSS 5.5v9.0v10.0+2 more2021-04-13
CVE-2021-0400 [MEDIUM] CWE-20 CVE-2021-0400: In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible inc
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation. This could lead to incorrect reporting of location data to emergency services with User execution privileges needed. User interaction is not needed for exploitation
nvd
CVE-2021-0597P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-07-14
CVE-2021-0597 [MEDIUM] CWE-862 CVE-2021-0597: In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrie
In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Andro
nvd
CVE-2021-0436P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-04-13
CVE-2021-0436 [MEDIUM] CWE-190 CVE-2021-0436: In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-176496160
nvd
CVE-2021-0620P4MEDIUMCVSS 5.5v10.0v11.02021-11-18
CVE-2021-0620 [MEDIUM] CWE-125 CVE-2021-0620: In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could l
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561381.
nvd
CVE-2021-0624P4MEDIUMCVSS 5.5v10.0v11.02021-11-18
CVE-2021-0624 [MEDIUM] CWE-125 CVE-2021-0624: In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could l
In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594988; Issue ID: ALPS05594988.
nvd
CVE-2021-0622P4MEDIUMCVSS 5.5v10.0v11.02021-11-18
CVE-2021-0622 [MEDIUM] CWE-125 CVE-2021-0622: In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could l
In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561388.
nvd
CVE-2021-0414P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0414 [MEDIUM] CWE-125 CVE-2021-0414: In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could l
In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561384; Issue ID: ALPS05561384.
nvd
CVE-2021-0616P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0616 [MEDIUM] CWE-125 CVE-2021-0616: In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could l
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561389; Issue ID: ALPS05561389.
nvd
CVE-2021-0617P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0617 [MEDIUM] CWE-125 CVE-2021-0617: In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could l
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561391; Issue ID: ALPS05561391.
nvd
CVE-2021-0618P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0618 [MEDIUM] CWE-125 CVE-2021-0618: In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could l
In ape extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561394; Issue ID: ALPS05561394.
nvd
CVE-2023-40098P4MEDIUMCVSS 5.5v12.0v12.1+6 more2023-12-04
CVE-2023-40098 [MEDIUM] CVE-2023-40098: In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification
In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd