cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 242 of 339
CVE-2020-0415P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-10-14
CVE-2020-0415 [MEDIUM] CVE-2020-0415: In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingInte In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-156020795
nvd
CVE-2022-20515P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20515 [MEDIUM] CWE-610 CVE-2022-20515: In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protec In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A
nvd
CVE-2020-0055P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-10
CVE-2020-0055 [MEDIUM] CWE-125 CVE-2020-0055: In l2c_link_process_num_completed_pkts of l2c_link.cc, there is a possible out of bounds read due to In l2c_link_process_num_completed_pkts of l2c_link.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141617601
nvd
CVE-2018-9544P4MEDIUMCVSS 5.5v9.02018-11-14
CVE-2018-9544 [MEDIUM] CWE-125 CVE-2018-9544: In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113037220
nvd
CVE-2021-0309P4MEDIUMCVSS 5.5v8.0v8.1+8 more2021-01-11
CVE-2021-0309 [MEDIUM] CVE-2021-0309: In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to lo In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disclosure and account access with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-158480899.
nvd
CVE-2019-2103P4MEDIUMCVSS 5.5v9.0vAndroid-92019-09-05
CVE-2019-2103 [MEDIUM] CWE-200 CVE-2019-2103: In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant t In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-2187P4MEDIUMCVSS 5.5v7.1.1v7.1.2+5 more2019-10-11
CVE-2019-2187 [MEDIUM] CWE-125 CVE-2019-2187: In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an intege In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-
nvd
CVE-2017-13322P4MEDIUMCVSS 5.5v6.0v6.0.1+6 more2025-01-17
CVE-2017-13322 [MEDIUM] CWE-783 CVE-2017-13322: In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0424P4MEDIUMCVSS 5.5v9.0v10.0+2 more2020-11-10
CVE-2020-0424 [MEDIUM] CWE-125 CVE-2020-0424: In send_vc of res_send.cpp, there is a possible out of bounds read due to an incorrect bounds check. In send_vc of res_send.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-161362564
nvd
CVE-2020-0359P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0359 [MEDIUM] CWE-125 CVE-2020-0359: In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow. This could lea In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150303018
nvd
CVE-2020-0393P4MEDIUMCVSS 5.5v9.0v10.0+1 more2020-09-17
CVE-2020-0393 [MEDIUM] CWE-125 CVE-2020-0393: In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a miss In decrypt and decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-154123412
nvd
CVE-2022-20511P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20511 [MEDIUM] CWE-862 CVE-2022-20511: In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission che In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235821829
nvd
CVE-2022-20502P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-13
CVE-2022-20502 [MEDIUM] CWE-416 CVE-2022-20502: In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale ca In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222166527
nvd
CVE-2020-0410P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-10-14
CVE-2020-0410 [MEDIUM] CWE-732 CVE-2020-0410: In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent e In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-156021269
nvd
CVE-2020-0057P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-10
CVE-2020-0057 [MEDIUM] CWE-125 CVE-2020-0057: In btm_process_inq_results of btm_inq.cc, there is a possible out of bounds read due to a missing bo In btm_process_inq_results of btm_inq.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141620271
nvd
CVE-2020-0056P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-10
CVE-2020-0056 [MEDIUM] CWE-125 CVE-2020-0056: In btu_hcif_connection_comp_evt of btu_hcif.cc, there is a possible out of bounds read due to a miss In btu_hcif_connection_comp_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141619686
nvd
CVE-2020-0059P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-10
CVE-2020-0059 [MEDIUM] CWE-125 CVE-2020-0059: In btm_ble_batchscan_filter_track_adv_vse_cback of btm_ble_batchscan.cc, there is a possible out of In btm_ble_batchscan_filter_track_adv_vse_cback of btm_ble_batchscan.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142543524
nvd
CVE-2019-9243P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9243 [MEDIUM] CWE-125 CVE-2019-9243: In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This coul In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120905706
nvd
CVE-2020-0419P4MEDIUMCVSS 5.5v8.1v9.0+3 more2020-10-14
CVE-2020-0419 [MEDIUM] CWE-862 CVE-2020-0419: In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 And
nvd
CVE-2018-9548P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2018-12-06
CVE-2018-9548 [MEDIUM] CWE-862 CVE-2018-9548: In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missin In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.
nvd
Google Android vulnerabilities | cvebase