cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 240 of 339
CVE-2018-9566P4MEDIUMCVSS 5.7v7.0v7.1.1+4 more2018-12-06
CVE-2018-9566 [MEDIUM] CWE-125 CVE-2018-9566: In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a mi In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure when connecting to a malicious Bluetooth device with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 And
nvd
CVE-2017-0424P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-02-08
CVE-2017-0424 [MEDIUM] CWE-200 CVE-2017-0424: An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a spe An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a general bypass for a user level defense in depth or exploit mitigation technology in a privileged process. Product: Android. Versions: 6.0
nvd
CVE-2021-25444P4MEDIUMCVSS 5.5v8.1v9.0+1 more2021-08-05
CVE-2021-25444 [MEDIUM] CWE-20 CVE-2021-25444: An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom k An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
nvd
CVE-2014-9895P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9895 [MEDIUM] CVE-2014-9895: drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 o drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize certain data structures, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28750150 and Qualcomm internal bug CR570757, a different vulnerabi
nvd
CVE-2016-6720P4MEDIUMCVSS 5.5≥ 4.0, < 4.4.4≥ 5.0, < 5.0.2+3 more2016-12-13
CVE-2016-6720 [MEDIUM] CWE-200 CVE-2016-6720: An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4 An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sen
nvd
CVE-2020-0498P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0498 [MEDIUM] CWE-125 CVE-2020-0498: In decode_packed_entry_number of codebook.c, there is a possible out of bounds read due to a heap bu In decode_packed_entry_number of codebook.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160633884
nvd
CVE-2018-9552P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2018-12-06
CVE-2018-9552 [MEDIUM] CWE-787 CVE-2018-9552: In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bound In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Androi
nvd
CVE-2021-0674P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-12-17
CVE-2021-0674 [MEDIUM] CWE-125 CVE-2021-0674: In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06064258; Issue ID: ALPS06064237.
nvd
CVE-2016-6710P4MEDIUMCVSS 5.5≥ 5.0, < 5.0.2≥ 5.1, < 5.1.1+2 more2016-11-25
CVE-2016-6710 [MEDIUM] CWE-200 CVE-2016-6710: An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used
nvd
CVE-2016-3924P4MEDIUMCVSS 5.5v4.0v4.0.1+21 more2016-10-10
CVE-2016-3924 [MEDIUM] CWE-200 CVE-2016-3924: services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5. services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate EFFECT_CMD_SET_PARAM and EFFECT_CMD_SET_PARAM_DEFERRED commands, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 3020
nvd
CVE-2019-2179P4MEDIUMCVSS 5.5v7.1.1v7.1.2+4 more2019-09-05
CVE-2019-2179 [MEDIUM] CWE-125 CVE-2019-2179: In NDEF_MsgValidate of ndef_utils in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out o In NDEF_MsgValidate of ndef_utils in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2016-2427P4MEDIUMCVSS 5.5v5.0v5.0.1+4 more2016-04-18
CVE-2016-2427 [MEDIUM] CWE-200 CVE-2016-2427: The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via a crafted application, aka internal bug 26234568. NOTE: The vendor disputes the existence of this p
nvd
CVE-2020-0244P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0244 [MEDIUM] CWE-125 CVE-2020-0244: In writeBurstBufferBytes of SPDIFEncoder.cpp, there is a possible out of bounds read due to an incor In writeBurstBufferBytes of SPDIFEncoder.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no clear exfiltration path, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145262423
nvd
CVE-2020-0386P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-09-17
CVE-2020-0386 [MEDIUM] CWE-1021 CVE-2020-0386: In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insec In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8
nvd
CVE-2016-0821P4MEDIUMCVSS 5.5v6.0.12016-03-12
CVE-2016-0821 [MEDIUM] CVE-2016-0821: The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug
nvd
CVE-2020-0113P4MEDIUMCVSS 5.5v10.0vAndroid-10 Android-92020-06-10
CVE-2020-0113 [MEDIUM] CWE-125 CVE-2020-0113: In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-150944913
nvd
CVE-2021-0642P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-08-17
CVE-2021-0642 [MEDIUM] CWE-862 CVE-2021-0642: In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable ident In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Andr
nvd
CVE-2021-39742P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39742 [MEDIUM] CWE-862 CVE-2021-39742: In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-186405602
nvd
CVE-2019-9465P4MEDIUMCVSS 5.5fixed in 10.0vAndroid-102020-01-07
CVE-2019-9465 [MEDIUM] CVE-2019-9465: In the Titan M handling of cryptographic operations, there is a possible information disclosure due In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-133258003
nvd
CVE-2022-20413P4MEDIUMCVSS 5.5v10.0v11.0+4 more2022-10-11
CVE-2022-20413 [MEDIUM] CVE-2022-20413: In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235850634
nvd
Google Android vulnerabilities | cvebase