cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 246 of 339
CVE-2023-21344P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21344 [MEDIUM] CWE-203 CVE-2023-21344: In Job Scheduler, there is a possible way to determine whether an app is installed, without query pe In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21205P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21205 [MEDIUM] CWE-502 CVE-2023-21205: In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262245376
nvd
CVE-2023-21105P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-06-15
CVE-2023-21105 [MEDIUM] CWE-918 CVE-2023-21105: In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a co In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-26103656
nvd
CVE-2021-25382P4MEDIUMCVSS 5.5v8.0v8.1+3 more2021-04-23
CVE-2021-25382 [MEDIUM] CWE-285 CVE-2021-25382: An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
nvd
CVE-2023-21331P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21331 [MEDIUM] CWE-203 CVE-2023-21331: In InputMethod, there is a possible way to determine whether an app is installed, without query perm In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21335P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21335 [MEDIUM] CWE-203 CVE-2023-21335: In Settings, there is a possible way to determine whether an app is installed, without query permiss In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21336P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21336 [MEDIUM] CWE-203 CVE-2023-21336: In Input Method, there is a possible way to determine whether an app is installed, without query per In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-39753P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39753 [MEDIUM] CWE-862 CVE-2021-39753: In DomainVerificationService, there is a possible way to access app domain verification information In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-200035185
nvd
CVE-2021-39747P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39747 [MEDIUM] CWE-276 CVE-2021-39747: In Settings Provider, there is a possible way to list values of non-readable global settings due to In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-208268457
nvd
CVE-2021-39748P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39748 [MEDIUM] CWE-276 CVE-2021-39748: In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203777141
nvd
CVE-2025-27701P4MEDIUMCVSS 5.5vAndroid kernel2025-05-27
CVE-2025-27701 [MEDIUM] CWE-476 CVE-2025-27701: In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check, which can lead to local Temporary DoS or OOB Read, leading to information disclosure.
nvd
CVE-2023-48399P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48399 [MEDIUM] CWE-125 CVE-2023-48399: In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bound In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2023-48408P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48408 [MEDIUM] CWE-125 CVE-2023-48408: In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2023-48411P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48411 [MEDIUM] CWE-125 CVE-2023-48411: In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible ou In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2023-21330P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21330 [MEDIUM] CWE-203 CVE-2023-21330: In Overlay Manager, there is a possible way to determine whether an app is installed, without query In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-21764P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-07-06
CVE-2022-21764 [MEDIUM] CWE-862 CVE-2022-21764: In telecom service, there is a possible information disclosure due to a missing permission check. Th In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044717.
nvd
CVE-2022-21763P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-07-06
CVE-2022-21763 [MEDIUM] CWE-862 CVE-2022-21763: In telecom service, there is a possible information disclosure due to a missing permission check. Th In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044708.
nvd
CVE-2022-20115P4MEDIUMCVSS 5.5v12.0v12.1+1 more2022-05-10
CVE-2022-20115 [MEDIUM] CWE-862 CVE-2022-20115: In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base sta In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12
nvd
CVE-2022-20225P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-07-13
CVE-2022-20225 [MEDIUM] CWE-862 CVE-2022-20225: In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive i In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 And
nvd
CVE-2022-21749P4MEDIUMCVSS 5.5v11.0v12.02022-06-06
CVE-2022-21749 [MEDIUM] CWE-862 CVE-2022-21749: In telephony, there is a possible information disclosure due to a missing permission check. This cou In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511058; Issue ID: ALPS06511058.
nvd
Google Android vulnerabilities | cvebase