cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 245 of 339
CVE-2021-0562P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0562 [MEDIUM] CWE-125 CVE-2021-0562: In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect b In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176084648
nvd
CVE-2022-39905P4MEDIUMCVSS 5.5v10.0v11.0+2 more2022-12-08
CVE-2022-39905 [MEDIUM] CWE-285 CVE-2022-39905: Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allow Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.
nvd
CVE-2021-0619P4MEDIUMCVSS 5.5v10.0v11.02021-11-18
CVE-2021-0619 [MEDIUM] CWE-125 CVE-2021-0619: In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could l In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561395; Issue ID: ALPS05561395.
nvd
CVE-2021-0412P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0412 [MEDIUM] CWE-125 CVE-2021-0412: In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could l In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561366; Issue ID: ALPS05561366.
nvd
CVE-2021-0413P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0413 [MEDIUM] CWE-125 CVE-2021-0413: In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could l In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561379; Issue ID: ALPS05561379.
nvd
CVE-2020-27035P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27035 [MEDIUM] CWE-416 CVE-2020-27035: In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper l In priorLinearAllocation of C2AllocatorIon.cpp, there is a possible use-after-free due to improper locking. This could lead to local information disclosure in the media codec with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-152239213
nvd
CVE-2021-39666P4MEDIUMCVSS 5.5v11.0v12.0+1 more2022-02-11
CVE-2021-39666 [MEDIUM] CWE-125 CVE-2021-39666: In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input valid In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-204445255
nvd
CVE-2023-21283P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21283 [MEDIUM] CVE-2023-21283: In multiple functions of StatusHints.java, there is a possible way to reveal images across users due In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-39778P4MEDIUMCVSS 5.5v12.0vAndroid-12L2022-03-30
CVE-2021-39778 [MEDIUM] CWE-20 CVE-2021-39778: In Telecomm, there is a possible way to determine whether an app is installed, without query permiss In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-196406138
nvd
CVE-2021-39740P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39740 [MEDIUM] CWE-20 CVE-2021-39740: In Messaging, there is a possible way to bypass attachment restrictions due to improper input valida In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-209965112
nvd
CVE-2021-0428P4MEDIUMCVSS 5.5v10.0vAndroid-102021-04-13
CVE-2021-0428 [MEDIUM] CWE-862 CVE-2021-0428: In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifi In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173421434
nvd
CVE-2024-0017P4MEDIUMCVSS 5.5v11.0v12.0+8 more2024-02-16
CVE-2024-0017 [MEDIUM] CWE-863 CVE-2024-0017: In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permis In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-20264P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2022-20264 [MEDIUM] CWE-203 CVE-2022-20264: In Usage Stats Service, there is a possible way to determine whether an app is installed, without qu In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21334P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21334 [MEDIUM] CVE-2023-21334: In App Ops Service, there is a possible disclosure of information about installed packages due to a In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-33685P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-07-12
CVE-2022-33685 [MEDIUM] CWE-561 CVE-2022-33685: Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows atta Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.
nvd
CVE-2022-20092P4MEDIUMCVSS 5.5v11.0v12.02022-05-03
CVE-2022-20092 [MEDIUM] CWE-125 CVE-2022-20092: In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could le In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366061; Issue ID: ALPS06366061.
nvd
CVE-2022-20104P4MEDIUMCVSS 5.5v11.0v12.02022-05-03
CVE-2022-20104 [MEDIUM] CVE-2022-20104: In aee daemon, there is a possible information disclosure due to improper access control. This could In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06284104.
nvd
CVE-2021-0979P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-0979 [MEDIUM] CWE-276 CVE-2021-0979: In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of package In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pro
nvd
CVE-2023-21333P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21333 [MEDIUM] CWE-203 CVE-2023-21333: In Text Services, there is a possible way to determine whether an app is installed, without query pe In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21332P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21332 [MEDIUM] CWE-203 CVE-2023-21332: In Text Services, there is a possible way to determine whether an app is installed, without query pe In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase