cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 241 of 339
CVE-2020-0132P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0132 [MEDIUM] CWE-125 CVE-2020-0132: In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139473816
nvd
CVE-2023-35671P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-09-11
CVE-2023-35671 [MEDIUM] CWE-269 CVE-2023-35671: In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose N In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is no
nvd
CVE-2020-0454P4MEDIUMCVSS 5.5v9.0vAndroid-92020-11-10
CVE-2020-0454 [MEDIUM] CWE-862 CVE-2020-0454: In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of the current SSID with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-161370134
nvd
CVE-2020-0293P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0293 [MEDIUM] CWE-862 CVE-2020-0293: In Java network APIs, there is possible access to sensitive network state due to a missing permissio In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation in Android versions: Android-11, Android ID: A-141455849
nvd
CVE-2020-15583P4MEDIUMCVSS 5.5v8.0v8.1+2 more2020-07-07
CVE-2020-15583 [MEDIUM] CWE-22 CVE-2020-15583: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to system files. The Samsung ID is SVE-2020-17665 (July 2020).
nvd
CVE-2019-2228P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-12-06
CVE-2019-2228 [MEDIUM] CWE-125 CVE-2019-2228: In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. T In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-111
nvd
CVE-2018-9454P4MEDIUMCVSS 5.5v6.0v6.0.1+5 more2018-11-06
CVE-2018-9454 [MEDIUM] CWE-125 CVE-2018-9454: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds che In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0
nvd
CVE-2020-0398P4MEDIUMCVSS 5.5v10.0v11.0+1 more2020-10-14
CVE-2020-0398 [MEDIUM] CVE-2020-0398: In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent e In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-154323381
nvd
CVE-2018-9451P4MEDIUMCVSS 5.5v6.0v6.0.1+5 more2018-11-06
CVE-2018-9451 [MEDIUM] CWE-125 CVE-2018-9451: In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missi In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.
nvd
CVE-2018-9453P4MEDIUMCVSS 5.5v6.0v6.0.1+5 more2018-11-06
CVE-2018-9453 [MEDIUM] CWE-125 CVE-2018-9453: In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds c In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8
nvd
CVE-2016-2457P4MEDIUMCVSS 5.5v5.0v5.0.1+4 more2016-05-09
CVE-2016-2457 [MEDIUM] CWE-264 CVE-2016-2457: server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6. server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended restrictions on Wi-Fi configuration changes by leveraging guest access, aka internal bug 27411179.
nvd
CVE-2020-0396P4MEDIUMCVSS 5.5v8.0v8.1+3 more2020-09-17
CVE-2020-0396 [MEDIUM] CVE-2020-0396: In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-155094269
nvd
CVE-2020-0399P4MEDIUMCVSS 5.5v8.0v8.1+3 more2020-09-17
CVE-2020-0399 [MEDIUM] CVE-2020-0399: In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Andro
nvd
CVE-2019-1995P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2019-02-28
CVE-2019-1995 [MEDIUM] CVE-2019-1995: In ComposeActivityEmail of ComposeActivityEmail.java, there is a possible way to silently attach fil In ComposeActivityEmail of ComposeActivityEmail.java, there is a possible way to silently attach files to an email due to a confused deputy. This could lead to local information disclosure, sending files accessible to AOSP Mail to a remote email recipient, with no additional execution privileges needed. User interaction is not needed for exploitation. Product
nvd
CVE-2020-0395P4MEDIUMCVSS 5.5v8.0v8.1+3 more2020-09-17
CVE-2020-0395 [MEDIUM] CVE-2020-0395: In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-1541
nvd
CVE-2020-0397P4MEDIUMCVSS 5.5v8.0v8.1+3 more2020-09-17
CVE-2020-0397 [MEDIUM] CVE-2020-0397: In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-
nvd
CVE-2020-0249P4MEDIUMCVSS 5.5v8.0v8.1+3 more2020-08-11
CVE-2020-0249 [MEDIUM] CVE-2020-0249: In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a Pe In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-154719656
nvd
CVE-2020-0467P4MEDIUMCVSS 5.5v8.1v9.0+3 more2020-12-14
CVE-2020-0467 [MEDIUM] CWE-404 CVE-2020-0467: In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue. This could lead to local information disclosure of secure network traffic over a non-VPN link with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 A
nvd
CVE-2019-2053P4MEDIUMCVSS 5.5v7.0v7.1.1+5 more2019-05-08
CVE-2019-2053 [MEDIUM] CWE-125 CVE-2019-2053: In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missin In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 A
nvd
CVE-2021-0304P4MEDIUMCVSS 5.5v8.0v8.1+6 more2021-01-11
CVE-2021-0304 [MEDIUM] CWE-732 CVE-2021-0304: In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsaf In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-8.0, Android-8.1, Android-9;
nvd
Google Android vulnerabilities | cvebase