cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 254 of 339
CVE-2020-0104P4MEDIUMCVSS 5.5v9.0v10.0+1 more2020-05-14
CVE-2020-0104 [MEDIUM] CVE-2020-0104: In onShowingStateChanged of KeyguardStateMonitor.java, there is a possible inappropriate read due to In onShowingStateChanged of KeyguardStateMonitor.java, there is a possible inappropriate read due to a logic error. This could lead to local information disclosure of keyguard-protected data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144430870
nvd
CVE-2020-0378P4MEDIUMCVSS 5.5v9.0v10.0+2 more2020-10-14
CVE-2020-0378 [MEDIUM] CWE-862 CVE-2020-0378: In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-157748906
nvd
CVE-2019-2118P4MEDIUMCVSS 5.5v8.0v8.1+2 more2019-07-08
CVE-2019-2118 [MEDIUM] CWE-908 CVE-2019-2118: In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-130161842.
nvd
CVE-2018-9554P4MEDIUMCVSS 5.5v7.0v7.1.1+3 more2018-12-06
CVE-2018-9554 [MEDIUM] CWE-200 CVE-2018-9554: In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media f In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Androi
nvd
CVE-2019-2220P4MEDIUMCVSS 5.5v9.0v10.0+1 more2019-12-06
CVE-2019-2220 [MEDIUM] CVE-2019-2220: In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling application suspend. This could lead to local information disclosure no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-138636979
nvd
CVE-2020-0035P4MEDIUMCVSS 5.5v8.0v8.1+2 more2020-03-10
CVE-2020-0035 [MEDIUM] CWE-862 CVE-2020-0035: In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing per In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-140622024
nvd
CVE-2018-9457P4MEDIUMCVSS 5.5v8.0v8.1+1 more2018-11-14
CVE-2018-9457 [MEDIUM] CWE-862 CVE-2018-9457: In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Andro
nvd
CVE-2019-2104P4MEDIUMCVSS 5.5v8.0v8.1+2 more2019-07-08
CVE-2019-2104 [MEDIUM] CWE-908 CVE-2019-2104: In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uni In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-131356202
nvd
CVE-2020-0280P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0280 [MEDIUM] CWE-125 CVE-2020-0280: In nci_proc_ee_management_rsp of nci_hrcv.cc, there is a possible out of bounds read due to a missin In nci_proc_ee_management_rsp of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136565424
nvd
CVE-2019-2197P4MEDIUMCVSS 5.5v8.0v8.1+3 more2019-11-13
CVE-2019-2197 [MEDIUM] CWE-1188 CVE-2019-2197: In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due t In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Androi
nvd
CVE-2019-2183P4MEDIUMCVSS 5.5v9.0v10.0+1 more2019-10-11
CVE-2019-2183 [MEDIUM] CWE-200 CVE-2019-2183: In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypas In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching optimization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-136261465
nvd
CVE-2017-0388P4MEDIUMCVSS 5.5v6.0v6.0.1+2 more2017-01-12
CVE-2017-0388 [MEDIUM] CWE-200 CVE-2017-0388: An elevation of privilege vulnerability in the External Storage Provider could enable a local second An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Ver
nvd
CVE-2022-20482P4MEDIUMCVSS 5.5v12.0v12.1+2 more2022-12-13
CVE-2022-20482 [MEDIUM] CWE-400 CVE-2022-20482: In createNotificationChannel of NotificationManager.java, there is a possible way to make the device In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L
nvd
CVE-2020-0389P4MEDIUMCVSS 5.5v10.0v11.0+1 more2020-09-17
CVE-2020-0389 [MEDIUM] CVE-2020-0389: In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-156959408
nvd
CVE-2020-0187P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0187 [MEDIUM] CVE-2020-0187: In engineSetMode of BaseBlockCipher.java, there is a possible incorrect cryptographic algorithm chos In engineSetMode of BaseBlockCipher.java, there is a possible incorrect cryptographic algorithm chosen due to an incomplete comparison. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148517383
nvd
CVE-2020-0178P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0178 [MEDIUM] CWE-862 CVE-2020-0178: In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing perm In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local information disclosure of config flags with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143299398
nvd
CVE-2020-0500P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0500 [MEDIUM] CVE-2020-0500: In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due t In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154913391
nvd
CVE-2020-0426P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0426 [MEDIUM] CVE-2020-0426: In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lea In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154921790
nvd
CVE-2020-0296P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0296 [MEDIUM] CVE-2020-0296: In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent. In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153356209
nvd
CVE-2020-0297P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0297 [MEDIUM] CVE-2020-0297: In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent. This In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155183624
nvd
Google Android vulnerabilities | cvebase