cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 256 of 339
CVE-2020-0343P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0343 [MEDIUM] CWE-862 CVE-2020-0343: In NetworkStatsService, there is a possible access to protected data due to a missing permission che In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119672472
nvd
CVE-2020-0048P4MEDIUMCVSS 5.5v10.0vAndroid-102020-03-10
CVE-2020-0048 [MEDIUM] CWE-908 CVE-2020-0048: In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139417189
nvd
CVE-2019-9435P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9435 [MEDIUM] CWE-125 CVE-2019-9435: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80146682
nvd
CVE-2019-9249P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9249 [MEDIUM] CWE-125 CVE-2019-9249: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805
nvd
CVE-2019-9368P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9368 [MEDIUM] CWE-125 CVE-2019-9368: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79883568
nvd
CVE-2019-9312P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9312 [MEDIUM] CWE-125 CVE-2019-9312: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78288018
nvd
CVE-2019-9347P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9347 [MEDIUM] CWE-125 CVE-2019-9347: In the m4v_h263 codec, there is a possible out of bounds read due to a use after free. This could le In the m4v_h263 codec, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109891727
nvd
CVE-2019-9417P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9417 [MEDIUM] CWE-125 CVE-2019-9417: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111450079
nvd
CVE-2019-9289P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9289 [MEDIUM] CWE-125 CVE-2019-9289: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79883824
nvd
CVE-2019-9427P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9427 [MEDIUM] CWE-416 CVE-2019-9427: In Bluetooth, there is a possible information disclosure due to a use after free. This could lead to In Bluetooth, there is a possible information disclosure due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110166350
nvd
CVE-2019-9287P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9287 [MEDIUM] CWE-125 CVE-2019-9287: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78287084
nvd
CVE-2019-2124P4MEDIUMCVSS 5.5v7.1.1v7.1.2+4 more2019-09-05
CVE-2019-2124 [MEDIUM] CVE-2019-2124: In ComposeActivityEmailExternal of ComposeActivityEmailExternal.java in Android 7.1.1, 7.1.2, 8.0, 8 In ComposeActivityEmailExternal of ComposeActivityEmailExternal.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible way to silently attach files to an email due to a confused deputy. This could lead to local information disclosure.
nvd
CVE-2021-25393P4MEDIUMCVSS 5.5v10.0v11.02021-06-11
CVE-2021-25393 [MEDIUM] CWE-94 CVE-2021-25393: Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
nvd
CVE-2020-0284P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0284 [MEDIUM] CWE-862 CVE-2020-0284: In Telephony, there is a possible permission bypass due to a missing permission check. This could le In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253784
nvd
CVE-2020-0285P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0285 [MEDIUM] CWE-862 CVE-2020-0285: In Telephony, there is a possible permission bypass due to a missing permission check. This could le In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253479
nvd
CVE-2020-27097P4MEDIUMCVSS 5.5v11.0vAndroid 112021-01-26
CVE-2020-27097 [MEDIUM] CVE-2020-27097: In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140729426
nvd
CVE-2020-27025P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27025 [MEDIUM] CVE-2020-27025: In EapFailureNotifier.java and SimRequiredNotifier.java, there is a possible permission bypass due t In EapFailureNotifier.java and SimRequiredNotifier.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156008365
nvd
CVE-2020-0289P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0289 [MEDIUM] CWE-862 CVE-2020-0289: In PackageManager, there is a missing permission check. This could lead to local information disclos In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996872
nvd
CVE-2020-0288P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0288 [MEDIUM] CWE-862 CVE-2020-0288: In PackageManager, there is a missing permission check. This could lead to local information disclos In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153995991
nvd
CVE-2020-27041P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-27041 [MEDIUM] CVE-2020-27041: In showProvisioningNotification of ConnectivityService.java, there is an unsafe PendingIntent. This In showProvisioningNotification of ConnectivityService.java, there is an unsafe PendingIntent. This could lead to local information disclosure of notification data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154928507
nvd
Google Android vulnerabilities | cvebase