Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 244 of 339
CVE-2021-0601P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-07-14
CVE-2021-0601 [MEDIUM] CWE-415 CVE-2021-0601: In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free.
In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-180643802
nvd
CVE-2020-0496P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0496 [MEDIUM] CWE-416 CVE-2020-0496: In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due
In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due to a use-after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-149481220
nvd
CVE-2019-2229P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-12-06
CVE-2019-2229 [MEDIUM] CWE-862 CVE-2019-2229: In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing p
In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-13980387
nvd
CVE-2022-20011P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-05-10
CVE-2022-20011 [MEDIUM] CWE-862 CVE-2022-20011: In getArray of NotificationManagerService.java , there is a possible leak of one user notifications
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndro
nvd
CVE-2021-0704P4MEDIUMCVSS 5.5v9.0v10.0+2 more2021-12-15
CVE-2021-0704 [MEDIUM] CWE-281 CVE-2021-0704: In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, th
In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P
nvd
CVE-2022-20101P4MEDIUMCVSS 5.5v11.0v12.02022-05-03
CVE-2022-20101 [MEDIUM] CWE-22 CVE-2022-20101: In aee daemon, there is a possible information disclosure due to a path traversal. This could lead t
In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06270870.
nvd
CVE-2021-0471P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-04-13
CVE-2021-0471 [MEDIUM] CWE-125 CVE-2021-0471: In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflo
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444786
nvd
CVE-2023-44126P4MEDIUMCVSS 5.5≥ 8.0, ≤ 13.02023-09-27
CVE-2023-44126 [MEDIUM] CWE-925 CVE-2023-44126: The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states, durations, called numbers, contacts info, etc.
nvd
CVE-2023-44127P4MEDIUMCVSS 5.5≥ 8.0, ≤ 13.02023-09-27
CVE-2023-44127 [MEDIUM] CWE-927 CVE-2023-44127: he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launch
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact details and phone numbers.
nvd
CVE-2022-20527P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20527 [MEDIUM] CWE-125 CVE-2022-20527: In HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds che
In HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC firmware with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-229994861
nvd
CVE-2022-20036P4MEDIUMCVSS 5.5v10.0v11.02022-02-09
CVE-2022-20036 [MEDIUM] CWE-20 CVE-2022-20036: In ion driver, there is a possible information disclosure due to an incorrect bounds check. This cou
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID: ALPS06171689.
nvd
CVE-2022-20037P4MEDIUMCVSS 5.5v10.0v11.02022-02-09
CVE-2022-20037 [MEDIUM] CWE-20 CVE-2022-20037: In ion driver, there is a possible information disclosure due to an incorrect bounds check. This cou
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID: ALPS06171705.
nvd
CVE-2022-20017P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-02-09
CVE-2022-20017 [MEDIUM] CWE-20 CVE-2022-20017: In ion driver, there is a possible information disclosure due to an incorrect bounds check. This cou
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862991; Issue ID: ALPS05862991.
nvd
CVE-2021-0682P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-10-06
CVE-2021-0682 [MEDIUM] CWE-862 CVE-2021-0682: In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of noti
In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10
nvd
CVE-2023-40075P4MEDIUMCVSS 5.5v11.0v12.0+8 more2023-12-04
CVE-2023-40075 [MEDIUM] CVE-2023-40075: In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited
In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0653P4MEDIUMCVSS 5.5v9.0v10.0+2 more2021-12-15
CVE-2021-0653 [MEDIUM] CWE-862 CVE-2021-0653: In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a tr
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android
nvd
CVE-2021-0693P4MEDIUMCVSS 5.5v11.0vAndroid-112021-10-06
CVE-2021-0693 [MEDIUM] CVE-2021-0693: In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from
In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-184046948
nvd
CVE-2021-0423P4MEDIUMCVSS 5.5v10.0v11.02021-09-27
CVE-2021-0423 [MEDIUM] CWE-665 CVE-2021-0423: In memory management driver, there is a possible information disclosure due to uninitialized data. T
In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05385714.
nvd
CVE-2021-0421P4MEDIUMCVSS 5.5v10.0v11.02021-09-27
CVE-2021-0421 [MEDIUM] CWE-120 CVE-2021-0421: In memory management driver, there is a possible information disclosure due to a missing bounds chec
In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381235.
nvd
CVE-2021-0425P4MEDIUMCVSS 5.5v10.0v11.02021-09-27
CVE-2021-0425 [MEDIUM] CVE-2021-0425: In memory management driver, there is a possible side channel information disclosure. This could lea
In memory management driver, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05400059.
nvd