cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 243 of 339
CVE-2016-0824P4MEDIUMCVSS 5.3v6.0v6.0.12016-03-12
CVE-2016-0824 [MEDIUM] CWE-200 CVE-2016-0824: libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive inf libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25765591.
nvdosv
CVE-2020-0323P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0323 [MEDIUM] CWE-125 CVE-2020-0323: In libavb, there is a possible out of bounds read due to a missing bounds check. This could lead to In libavb, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146516087
nvd
CVE-2020-0197P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0197 [MEDIUM] CWE-125 CVE-2020-0197: In InitDataParser::parsePssh of InitDataParser.cpp, there is a possible out of bounds read due to a In InitDataParser::parsePssh of InitDataParser.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137370379
nvd
CVE-2020-0100P4MEDIUMCVSS 5.5v8.0v8.1+1 more2020-05-14
CVE-2020-0100 [MEDIUM] CWE-125 CVE-2020-0100: In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to local information disclosure of data from a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-8.0Android ID: A-150156584
nvd
CVE-2019-2226P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-12-06
CVE-2019-2226 [MEDIUM] CWE-125 CVE-2019-2226: In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper ca In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure in the Bluetooth server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140
nvd
CVE-2019-2209P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-11-13
CVE-2019-2209 [MEDIUM] CWE-125 CVE-2019-2209: In BTA_DmPinReply of bta_dm_api.cc, there is a possible out of bounds read due to an incorrect bound In BTA_DmPinReply of bta_dm_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139287605
nvd
CVE-2024-0047P4MEDIUMCVSS 5.5v14.0v142024-03-11
CVE-2024-0047 [MEDIUM] CWE-502 CVE-2024-0047: In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0468P4MEDIUMCVSS 5.5v10.0v11.0+1 more2020-12-14
CVE-2020-0468 [MEDIUM] CWE-862 CVE-2020-0468: In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Andr
nvd
CVE-2019-2088P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-15
CVE-2019-2088 [MEDIUM] CWE-125 CVE-2019-2088: In StatsService, there is a possible out of bounds read. This could lead to local information disclo In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were not enabled, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-143895055
nvd
CVE-2020-27027P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27027 [MEDIUM] CWE-125 CVE-2020-27027: In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-122358602
nvd
CVE-2020-0329P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0329 [MEDIUM] CWE-125 CVE-2020-0329: In the OMX encoder, there is a possible out of bounds read due to invalid input validation. This cou In the OMX encoder, there is a possible out of bounds read due to invalid input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-63522940
nvd
CVE-2020-0125P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0125 [MEDIUM] CWE-125 CVE-2020-0125: In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead t In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137282168
nvd
CVE-2020-0156P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0156 [MEDIUM] CWE-125 CVE-2020-0156: In NxpNfc::ioctl of NxpNfc.cpp, there is a possible out of bounds read due to a missing bounds check In NxpNfc::ioctl of NxpNfc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736127
nvd
CVE-2020-0185P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0185 [MEDIUM] CWE-125 CVE-2020-0185: In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missin In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-79945152
nvd
CVE-2026-28573P4MEDIUMCVSS 5.5v14.0v16.0+2 more2026-06-18
CVE-2026-28573 [MEDIUM] CWE-862 CVE-2026-28573: In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-2117P4MEDIUMCVSS 5.5v7.0v7.1.1+5 more2019-07-08
CVE-2019-2117 [MEDIUM] CWE-862 CVE-2019-2117: In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead to local information disclosure about carrier systems with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1
nvd
CVE-2020-27098P4MEDIUMCVSS 5.5v11.0vAndroid 112021-01-26
CVE-2020-27098 [MEDIUM] CVE-2020-27098: In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contac In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-138791358
nvd
CVE-2020-0493P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0493 [MEDIUM] CWE-20 CVE-2020-0493: In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to i In CPDF_SampledFunc::v_Call of cpdf_sampledfunc.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150615407
nvd
CVE-2020-27032P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27032 [MEDIUM] CWE-862 CVE-2020-27032: In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data d In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150857259
nvd
CVE-2021-0599P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-07-14
CVE-2021-0599 [MEDIUM] CWE-610 CVE-2021-0599: In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive i In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadcasted intent due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 And
nvd
Google Android vulnerabilities | cvebase