Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 234 of 339
CVE-2023-42741P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42741 [MEDIUM] CWE-862 CVE-2023-42741: In telecom service, there is a possible way to write permission usage records of an app due to a mis
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42749P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42749 [MEDIUM] CWE-862 CVE-2023-42749: In enginnermode service, there is a possible way to write permission usage records of an app due to
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-21294P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21294 [MEDIUM] CWE-862 CVE-2023-21294: In Slice, there is a possible disclosure of installed packages due to a missing permission check. Th
In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21019P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-21019 [MEDIUM] CWE-125 CVE-2023-21019: In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap b
In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-242379731
nvd
CVE-2023-21200P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21200 [MEDIUM] CWE-125 CVE-2023-21200: In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper
In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236688764
nvd
CVE-2023-21198P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21198 [MEDIUM] CWE-125 CVE-2023-21198: In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing
In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245517503
nvd
CVE-2023-21168P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21168 [MEDIUM] CWE-125 CVE-2023-21168: In convertCbYCrY of ColorConverter.cpp, there is a possible out of bounds read due to a missing boun
In convertCbYCrY of ColorConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-253270285
nvd
CVE-2023-20980P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20980 [MEDIUM] CWE-125 CVE-2023-20980: In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a mis
In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260230274
nvd
CVE-2023-20952P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-03-24
CVE-2023-20952 [MEDIUM] CWE-787 CVE-2023-20952: In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing
In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-18680351
nvd
CVE-2023-21292P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21292 [MEDIUM] CVE-2023-21292: In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to o
In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40124P4MEDIUMCVSS 5.5v11.0v12.0+6 more2024-02-15
CVE-2023-40124 [MEDIUM] CWE-125 CVE-2023-40124: In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead
In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21384P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21384 [MEDIUM] CVE-2023-21384: In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent.
In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40139P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-10-27
CVE-2023-40139 [MEDIUM] CWE-610 CVE-2023-40139: In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused de
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21277P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-08-14
CVE-2023-21277 [MEDIUM] CVE-2023-21277: In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a mis
In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21279P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-08-14
CVE-2023-21279 [MEDIUM] CVE-2023-21279: In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy
In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-48371P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-05-09
CVE-2022-48371 [MEDIUM] CWE-862 CVE-2022-48371: In dialer service, there is a possible missing permission check. This could lead to local informatio
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
nvd
CVE-2022-48242P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-05-09
CVE-2022-48242 [MEDIUM] CWE-862 CVE-2022-48242: In telephony service, there is a possible missing permission check. This could lead to local informa
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
nvd
CVE-2022-48370P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-05-09
CVE-2022-48370 [MEDIUM] CWE-862 CVE-2022-48370: In dialer service, there is a possible missing permission check. This could lead to local informatio
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
nvd
CVE-2023-21312P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21312 [MEDIUM] CVE-2023-21312: In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could le
In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21289P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21289 [MEDIUM] CVE-2023-21289: In multiple locations, there is a possible bypass of a multi user security boundary due to a confuse
In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd