cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 235 of 339
CVE-2022-47367P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47367 [MEDIUM] CWE-862 CVE-2022-47367: In bluetooth driver, there is a missing permission check. This could lead to local information discl In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-21376P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21376 [MEDIUM] CWE-269 CVE-2023-21376: In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This c In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21271P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-08-14
CVE-2023-21271 [MEDIUM] CWE-125 CVE-2023-21271: In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper inpu In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21112P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21112 [MEDIUM] CWE-125 CVE-2023-21112: In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252763983
nvd
CVE-2023-21080P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-21080 [MEDIUM] CWE-125 CVE-2023-21080: In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-245916076
nvd
CVE-2023-21368P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21368 [MEDIUM] CWE-125 CVE-2023-21368: In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to loc In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48584P4MEDIUMCVSS 5.5v16.0v162025-12-08
CVE-2025-48584 [MEDIUM] CWE-400 CVE-2025-48584: In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per- In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9441P4MEDIUMCVSS 5.5v6.0v6.0.1+8 more2024-12-03
CVE-2018-9441 [MEDIUM] CWE-125 CVE-2018-9441: In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-40112P4MEDIUMCVSS 5.5v11.0v112024-02-15
CVE-2023-40112 [MEDIUM] CWE-125 CVE-2023-40112: In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. Th In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21352P4MEDIUMCVSS 5.5v14.0v142023-10-30
CVE-2023-21352 [MEDIUM] CWE-125 CVE-2023-21352: In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to loc In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21309P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21309 [MEDIUM] CWE-125 CVE-2023-21309: In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-42647P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-11-01
CVE-2023-42647 [MEDIUM] CVE-2023-42647: In Ifaa service, there is a possible way to write permission usage records of an app due to a missin In Ifaa service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42645P4MEDIUMCVSS 5.5v11.02023-11-01
CVE-2023-42645 [MEDIUM] CVE-2023-42645: In sim service, there is a possible way to write permission usage records of an app due to a missing In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-21311P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21311 [MEDIUM] CWE-863 CVE-2023-21311: In Settings, there is a possible way to control private DNS settings from a secondary user due to a In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21321P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21321 [MEDIUM] CWE-862 CVE-2023-21321: In Package Manager, there is a possible cross-user settings disclosure due to a missing permission c In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21366P4MEDIUMCVSS 5.5fixed in 14.0v14.0+1 more2023-10-30
CVE-2023-21366 [MEDIUM] CVE-2023-21366: In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecur In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21141P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-06-15
CVE-2023-21141 [MEDIUM] CWE-862 CVE-2023-21141: In several functions of several files, there is a possible way to access developer mode traces due t In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A
nvd
CVE-2024-29780P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-29780 [MEDIUM] CWE-908 CVE-2024-29780: In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitiali In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-48354P4MEDIUMCVSS 5.5v11.0v12.0+1 more2024-01-18
CVE-2023-48354 [MEDIUM] CWE-20 CVE-2023-48354: In telephone service, there is a possible improper input validation. This could lead to local inform In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-32825P4MEDIUMCVSS 5.5v13.02023-11-06
CVE-2023-32825 [MEDIUM] CWE-125 CVE-2023-32825: In bluethooth service, there is a possible out of bounds reads due to improper input validation. Thi In bluethooth service, there is a possible out of bounds reads due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07884130; Issue ID: ALPS07884130.
nvd
Google Android vulnerabilities | cvebase