Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 232 of 339
CVE-2022-20481P4MEDIUMCVSS 5.5v10.0v11.0+4 more2023-02-28
CVE-2022-20481 [MEDIUM] CVE-2022-20481: In multiple files, there is a possible way to preserve WiFi settings due to residual data after a re
In multiple files, there is a possible way to preserve WiFi settings due to residual data after a reset. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-241927115
nvd
CVE-2021-0556P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0556 [MEDIUM] CWE-125 CVE-2021-0556: In getBlockSum of fastcodemb.cpp, there is a possible out of bounds read due to a heap buffer overfl
In getBlockSum of fastcodemb.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172716941
nvd
CVE-2021-0563P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0563 [MEDIUM] CWE-125 CVE-2021-0563: In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to
In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172908358
nvd
CVE-2021-0689P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-10-06
CVE-2021-0689 [MEDIUM] CWE-125 CVE-2021-0689: In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missin
In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-190188264
nvd
CVE-2021-0377P4MEDIUMCVSS 5.5v11.0vAndroid-112021-03-10
CVE-2021-0377 [MEDIUM] CWE-20 CVE-2021-0377: In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to im
In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation. This could lead to a local bypass of defense in depth protections with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160800689
nvd
CVE-2021-25344P4MEDIUMCVSS 5.5v10.0v11.02021-03-04
CVE-2021-25344 [MEDIUM] CWE-862 CVE-2021-25344: Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.
nvd
CVE-2023-21267P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21267 [MEDIUM] CWE-200 CVE-2023-21267: In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-1001P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1001 [MEDIUM] CWE-125 CVE-2021-1001: In PVInitVideoEncoder of mp4enc_api.cpp, there is a possible out of bounds read due to a heap buffer
In PVInitVideoEncoder of mp4enc_api.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-190435883
nvd
CVE-2021-0998P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-0998 [MEDIUM] CWE-125 CVE-2021-0998: In 'ih264e_find_bskip_params()' of ih264e_me.c, there is a possible out of bounds read due to a heap
In 'ih264e_find_bskip_params()' of ih264e_me.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193442575
nvd
CVE-2021-0644P4MEDIUMCVSS 5.5v10.0v11.0+1 more2021-10-06
CVE-2021-0644 [MEDIUM] CWE-200 CVE-2021-0644: In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retriev
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID:
nvd
CVE-2021-0584P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-08-17
CVE-2021-0584 [MEDIUM] CWE-125 CVE-2021-0584: In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input
In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-179289794
nvd
CVE-2021-0621P4MEDIUMCVSS 5.5v10.0v11.02021-11-18
CVE-2021-0621 [MEDIUM] CWE-190 CVE-2021-0621: In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead
In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561383.
nvd
CVE-2021-0623P4MEDIUMCVSS 5.5v10.0v11.02021-11-18
CVE-2021-0623 [MEDIUM] CWE-190 CVE-2021-0623: In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead
In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05585817.
nvd
CVE-2021-0615P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0615 [MEDIUM] CWE-125 CVE-2021-0615: In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead
In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561369; Issue ID: ALPS05561369.
nvd
CVE-2021-0411P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0411 [MEDIUM] CWE-125 CVE-2021-0411: In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead
In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561362; Issue ID: ALPS05561362.
nvd
CVE-2023-35680P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-09-11
CVE-2023-35680 [MEDIUM] CWE-470 CVE-2023-35680: In multiple locations, there is a possible way to import contacts belonging to other users due to a
In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21173P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21173 [MEDIUM] CWE-862 CVE-2023-21173: In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's netwo
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-26274185
nvd
CVE-2021-0966P4MEDIUMCVSS 5.5v11.0v12.0+1 more2021-12-15
CVE-2021-0966 [MEDIUM] CWE-909 CVE-2021-0966: In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted pa
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder transactions with no additional execution privileges needed. User interaction is not needed for exploita
nvd
CVE-2022-20205P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-06-15
CVE-2022-20205 [MEDIUM] CWE-20 CVE-2022-20205: In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due
In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-215212561
nvd
CVE-2022-25819P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-03-10
CVE-2022-25819 [MEDIUM] CWE-125 CVE-2022-25819: OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to vie
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.
nvd