Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 233 of 339
CVE-2022-33721P4MEDIUMCVSS 5.5v12.02022-08-05
CVE-2022-33721 [MEDIUM] CWE-94 CVE-2022-33721: A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers t
A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.
nvd
CVE-2023-48412P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48412 [MEDIUM] CVE-2023-48412: In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic e
In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21295P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21295 [MEDIUM] CVE-2023-21295: In SliceManagerService, there is a possible way to check if a content provider is installed due to a
In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0643P4MEDIUMCVSS 5.5v10.0v11.0+2 more2021-10-22
CVE-2021-0643 [MEDIUM] CWE-862 CVE-2021-0643: In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term
In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 An
nvd
CVE-2023-21293P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21293 [MEDIUM] CWE-203 CVE-2023-21293: In PackageManagerNative, there is a possible way to determine whether an app is installed, without q
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-33715P4MEDIUMCVSS 5.5v11.0v12.02022-08-05
CVE-2022-33715 [MEDIUM] CWE-20 CVE-2022-33715: Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 R
Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.
nvd
CVE-2024-43082P4MEDIUMCVSS 5.5v12.0v12.1+2 more2024-11-13
CVE-2024-43082 [MEDIUM] CWE-125 CVE-2024-43082: In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due t
In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-42718P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42718 [MEDIUM] CWE-668 CVE-2023-42718: In dialer, there is a possible way to write permission usage records of an app due to a missing perm
In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-48401P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48401 [MEDIUM] CWE-125 CVE-2023-48401: In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an inc
In GetSizeOfEenlRecords of protocoladapter.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21329P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21329 [MEDIUM] CWE-862 CVE-2023-21329: In Activity Manager, there is a possible way to determine whether an app is installed due to a missi
In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21340P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21340 [MEDIUM] CWE-862 CVE-2023-21340: In Telecomm, there is a possible way to get the call state due to a missing permission check. This c
In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21338P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21338 [MEDIUM] CWE-203 CVE-2023-21338: In Input Method, there is a possible way to determine whether an app is installed, without query per
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21394P4MEDIUMCVSS 5.5fixed in 14.0v13+3 more2023-10-30
CVE-2023-21394 [MEDIUM] CVE-2023-21394: In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from an
In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20393P4MEDIUMCVSS 5.5v11.0v12.0+2 more2022-09-13
CVE-2022-20393 [MEDIUM] CWE-191 CVE-2022-20393: In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LA
nvd
CVE-2024-43084P4MEDIUMCVSS 5.5v12.0v12.1+8 more2024-11-13
CVE-2024-43084 [MEDIUM] CWE-1021 CVE-2024-43084: In visitUris of multiple files, there is a possible information disclosure due to a confused deputy.
In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-42698P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42698 [MEDIUM] CWE-862 CVE-2023-42698: In omacp service, there is a possible way to write permission usage records of an app due to a missi
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42730P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42730 [MEDIUM] CWE-862 CVE-2023-42730: In IMS service, there is a possible way to write permission usage records of an app due to a missing
In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42697P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42697 [MEDIUM] CWE-862 CVE-2023-42697: In omacp service, there is a possible way to write permission usage records of an app due to a missi
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42699P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42699 [MEDIUM] CWE-862 CVE-2023-42699: In omacp service, there is a possible way to write permission usage records of an app due to a missi
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42737P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42737 [MEDIUM] CWE-862 CVE-2023-42737: In telecom service, there is a possible way to write permission usage records of an app due to a mis
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd