cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 247 of 339
CVE-2022-21748P4MEDIUMCVSS 5.5v11.0v12.02022-06-06
CVE-2022-21748 [MEDIUM] CWE-862 CVE-2022-21748: In telephony, there is a possible information disclosure due to a missing permission check. This cou In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06511030; Issue ID: ALPS06511030.
nvd
CVE-2023-35679P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-09-11
CVE-2023-35679 [MEDIUM] CWE-125 CVE-2023-35679: In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized da In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-20350P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-08-10
CVE-2022-20350 [MEDIUM] CWE-20 CVE-2022-20350: In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the vic In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android
nvd
CVE-2022-20353P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-08-10
CVE-2022-20353 [MEDIUM] CWE-20 CVE-2022-20353: In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid
nvd
CVE-2023-42675P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42675 [MEDIUM] CWE-862 CVE-2023-42675: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42672P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42672 [MEDIUM] CWE-862 CVE-2023-42672: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42676P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42676 [MEDIUM] CWE-862 CVE-2023-42676: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42704P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42704 [MEDIUM] CWE-862 CVE-2023-42704: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42677P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42677 [MEDIUM] CWE-862 CVE-2023-42677: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42673P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42673 [MEDIUM] CWE-862 CVE-2023-42673: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42671P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42671 [MEDIUM] CWE-862 CVE-2023-42671: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42674P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42674 [MEDIUM] CWE-862 CVE-2023-42674: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42678P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42678 [MEDIUM] CWE-862 CVE-2023-42678: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42705P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42705 [MEDIUM] CWE-862 CVE-2023-42705: In imsservice, there is a possible way to write permission usage records of an app due to a missing In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2024-43086P4MEDIUMCVSS 5.5v12.0v12.1+8 more2024-11-13
CVE-2024-43086 [MEDIUM] CWE-276 CVE-2024-43086: In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account c In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20973P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20973 [MEDIUM] CWE-125 CVE-2023-20973: In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a mi In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260568245
nvd
CVE-2023-20974P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20974 [MEDIUM] CWE-125 CVE-2023-20974: In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bound In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260078907
nvd
CVE-2022-36854P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-09-09
CVE-2022-36854 [MEDIUM] CWE-20 CVE-2022-36854: Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker acc Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.
nvd
CVE-2023-21304P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21304 [MEDIUM] CWE-203 CVE-2023-21304: In Content Service, there is a possible way to determine whether an app is installed, without query In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20979P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20979 [MEDIUM] CWE-125 CVE-2023-20979: In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259939364
nvd
Google Android vulnerabilities | cvebase