cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 255 of 339
CVE-2020-11836P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-02-06
CVE-2020-11836 [MEDIUM] CVE-2020-11836: OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulner OPPO Android Phone with MTK chipset and Android 8.1/9/10/11 versions have an information leak vulnerability. The “adb shell getprop ro.vendor.aee.enforcing” or “adb shell getprop ro.vendor.aee.enforcing” return no.
nvd
CVE-2020-0250P4MEDIUMCVSS 5.5v10.0vAndroid-102020-08-11
CVE-2020-0250 [MEDIUM] CWE-862 CVE-2020-0250: In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of location data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-154934934
nvd
CVE-2019-2056P4MEDIUMCVSS 5.5v10.0vAndroid-102020-04-17
CVE-2019-2056 [MEDIUM] CVE-2019-2056: There is a possible disclosure of RAM using a shared crypto key due to improperly used crypto. This There is a possible disclosure of RAM using a shared crypto key due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140879284
nvd
CVE-2020-0020P4MEDIUMCVSS 5.5v10.0vAndroid-102020-02-13
CVE-2020-0020 [MEDIUM] CWE-119 CVE-2020-0020: In getAttributeRange of ExifInterface.java, there is a possible failure to redact location informati In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143118731
nvd
CVE-2019-2110P4MEDIUMCVSS 5.5v9.0vAndroid-92019-10-11
CVE-2019-2110 [MEDIUM] CWE-862 CVE-2019-2110: In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-69703445
nvd
CVE-2018-9487P4MEDIUMCVSS 5.5v8.0v8.1+3 more2024-11-20
CVE-2018-9487 [MEDIUM] CVE-2018-9487: In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due to a bad uid check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2020-0327P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0327 [MEDIUM] CWE-862 CVE-2020-0327: In core networking, there is a missing permission check. This could lead to local information disclo In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129151407
nvd
CVE-2020-0308P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0308 [MEDIUM] CVE-2020-0308: In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent. This could In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153654357
nvd
CVE-2021-0604P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-07-14
CVE-2021-0604 [MEDIUM] CVE-2021-0604: In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID
nvd
CVE-2020-27039P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27039 [MEDIUM] CVE-2020-27039: In postNotification of ServiceRecord.java, there is a possible permission bypass due to an unsafe Pe In postNotification of ServiceRecord.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153878498
nvd
CVE-2020-27034P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27034 [MEDIUM] CVE-2020-27034: In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153556754
nvd
CVE-2020-0437P4MEDIUMCVSS 5.5v8.0v8.1+4 more2020-11-10
CVE-2020-0437 [MEDIUM] CWE-862 CVE-2020-0437: In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing p In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Androi
nvd
CVE-2020-0390P4MEDIUMCVSS 5.5v10.0v11.0+1 more2020-09-17
CVE-2020-0390 [MEDIUM] CWE-276 CVE-2020-0390: In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local inform In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-157598026
nvd
CVE-2020-0337P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0337 [MEDIUM] CVE-2020-0337: In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy. This c In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124329382
nvd
CVE-2021-0931P4MEDIUMCVSS 5.5v9.0v10.0+3 more2021-12-15
CVE-2021-0931 [MEDIUM] CVE-2021-0931: In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs due to missing data filtering. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-180747689
nvd
CVE-2020-0425P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0425 [MEDIUM] CVE-2020-0425: There is a possible way to view notifications even when the "Lockdown" feature is on. This could lea There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124000380
nvd
CVE-2020-0107P4MEDIUMCVSS 5.5v10.0vAndroid-102020-07-17
CVE-2020-0107 [MEDIUM] CWE-862 CVE-2020-0107: In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to imp In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146570216
nvd
CVE-2020-0101P4MEDIUMCVSS 5.5v8.0v8.1+3 more2020-05-14
CVE-2020-0101 [MEDIUM] CWE-908 CVE-2020-0101: In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitiali In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144767096
nvd
CVE-2020-0265P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0265 [MEDIUM] CWE-862 CVE-2020-0265: In Telephony, there are possible leaks of sensitive data due to missing permission checks. This coul In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150155839
nvd
CVE-2020-0314P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0314 [MEDIUM] CWE-862 CVE-2020-0314: In AudioService, there are missing permission checks. This could lead to local information disclosur In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934920
nvd
Google Android vulnerabilities | cvebase