cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 253 of 339
CVE-2021-0480P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-06-11
CVE-2021-0480 [MEDIUM] CVE-2021-0480: In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensi In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-174493336
nvd
CVE-2020-27026P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27026 [MEDIUM] CWE-203 CVE-2020-27026: During boot, the device unlock interface behaves differently depending on if a fingerprint registere During boot, the device unlock interface behaves differently depending on if a fingerprint registered to the device is present. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-79776455
nvd
CVE-2017-11002P4MEDIUMCVSS 5.5≤ 8.02017-09-21
CVE-2017-11002 [MEDIUM] CWE-125 CVE-2017-11002: In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a v In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.
nvd
CVE-2016-6746P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6746 [MEDIUM] CWE-200 CVE-2016-6746: An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Android ID: A-30955105. References: NVIDIA N-CVE-2016-67
nvd
CVE-2020-0023P4MEDIUMCVSS 5.5v10.0vAndroid-102020-02-13
CVE-2020-0023 [MEDIUM] CWE-862 CVE-2020-0023: In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user conta In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetooth connection, with User execution privileges needed. User interaction is not needed for exploitation
nvd
CVE-2020-0258P4MEDIUMCVSS 5.5v10.0vAndroid-102020-08-11
CVE-2020-0258 [MEDIUM] CWE-459 CVE-2020-0258: In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local in In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-157598956
nvd
CVE-2020-0121P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-10
CVE-2020-0121 [MEDIUM] CVE-2020-0121: In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic er In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148180766
nvd
CVE-2020-0453P4MEDIUMCVSS 5.5v8.0v8.1+2 more2020-11-10
CVE-2020-0453 [MEDIUM] CVE-2020-0453: In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an u In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-8.0 Android-8.1Android ID: A-159060474
nvd
CVE-2018-9543P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2018-11-14
CVE-2018-9543 [MEDIUM] CWE-200 CVE-2018-9543: In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This could lead to local information disclosure after factory reset with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Androi
nvd
CVE-2020-0400P4MEDIUMCVSS 5.5v10.0v11.0+1 more2020-10-14
CVE-2020-0400 [MEDIUM] CVE-2020-0400: In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-153356561
nvd
CVE-2020-0239P4MEDIUMCVSS 5.5v9.0v10.0+1 more2020-08-11
CVE-2020-0239 [MEDIUM] CWE-862 CVE-2020-0239: In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadat In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This could lead to local information disclosure from a file (eg. a photo) containing location metadata with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An
nvd
CVE-2019-2180P4MEDIUMCVSS 5.5v8.0v8.1+2 more2019-09-05
CVE-2019-2180 [MEDIUM] CWE-125 CVE-2019-2180: In ippSetValueTag of ipp.c in Android 8.0, 8.1 and 9, there is a possible out of bounds read due to In ippSetValueTag of ipp.c in Android 8.0, 8.1 and 9, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure from the printer service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9589P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2019-02-11
CVE-2018-9589 [MEDIUM] CWE-125 CVE-2018-9589: In ieee802_11_rx_wnmsleep_req of wnm_ap.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, In ieee802_11_rx_wnmsleep_req of wnm_ap.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi driver with no additional execution privileges needed. User interaction is not needed for explo
nvd
CVE-2020-0116P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-10
CVE-2020-0116 [MEDIUM] CVE-2020-0116: In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profil In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-151330809
nvd
CVE-2020-0248P4MEDIUMCVSS 5.5v10.0vAndroid-102020-08-11
CVE-2020-0248 [MEDIUM] CVE-2020-0248: In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a Pe In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-154627439
nvd
CVE-2019-2004P4MEDIUMCVSS 5.5v7.0v7.1.1+5 more2019-06-19
CVE-2019-2004 [MEDIUM] CWE-908 CVE-2019-2004: In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Andro
nvd
CVE-2019-2212P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-11-13
CVE-2019-2212 [MEDIUM] CWE-125 CVE-2019-2212: In poisson_distribution of random, there is an out of bounds read. This could lead to local informat In poisson_distribution of random, there is an out of bounds read. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139690488
nvd
CVE-2020-0246P4MEDIUMCVSS 5.5v10.0v11.0+1 more2020-10-14
CVE-2020-0246 [MEDIUM] CWE-862 CVE-2020-0246: In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-159062405
nvd
CVE-2020-0007P4MEDIUMCVSS 5.5v8.0v8.1+6 more2020-01-08
CVE-2020-0007 [MEDIUM] CWE-908 CVE-2020-0007: In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to un In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID:
nvd
CVE-2023-21284P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21284 [MEDIUM] CWE-20 CVE-2023-21284: In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the F In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase