Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 257 of 339
CVE-2019-20774P4MEDIUMCVSS 5.5v7.0v7.1+4 more2020-04-17
CVE-2019-20774 [MEDIUM] CVE-2019-20774: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 softwa
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A system service allows local retrieval of the user's password. The LG ID is LVE-SMP-190009 (August 2019).
nvd
CVE-2019-2113P4MEDIUMCVSS 5.5v9.0vAndroid-92019-07-08
CVE-2019-2113 [MEDIUM] CVE-2019-2113: In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to
In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset protection bypass with no additional privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122597079.
nvd
CVE-2020-0276P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0276 [MEDIUM] CWE-862 CVE-2020-0276: In Telephony, there is a possible permission bypass due to a missing permission check. This could le
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253586
nvd
CVE-2020-0106P4MEDIUMCVSS 5.5v10.0vAndroid-102020-05-14
CVE-2020-0106 [MEDIUM] CWE-862 CVE-2020-0106: In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a mis
In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148414207
nvd
CVE-2019-9272P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9272 [MEDIUM] CWE-863 CVE-2019-9272: In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a lo
In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to determine device location with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-11596047
nvd
CVE-2023-20910P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-03-24
CVE-2023-20910 [MEDIUM] CWE-400 CVE-2023-20910: In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due t
In add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0316P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0316 [MEDIUM] CWE-862 CVE-2020-0316: In Telephony, there is a missing permission check. This could lead to local information disclosure o
In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934919
nvd
CVE-2020-0372P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0372 [MEDIUM] CWE-862 CVE-2020-0372: In ActivityManager, there is a possible access to protected data due to a missing permission check.
In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119673147
nvd
CVE-2020-0317P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0317 [MEDIUM] CWE-862 CVE-2020-0317: In UsageStatsManager, there is a possible access to protected data due to a missing permission check
In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119671929
nvd
CVE-2020-0290P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0290 [MEDIUM] CWE-862 CVE-2020-0290: In PackageManager, there is a missing permission check. This could lead to local information disclos
In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996866
nvd
CVE-2021-0588P4MEDIUMCVSS 5.5v8.1v9.0+1 more2021-07-14
CVE-2021-0588 [MEDIUM] CWE-668 CVE-2021-0588: In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missin
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-177238342
nvd
CVE-2022-20531P4MEDIUMCVSS 5.5v142022-12-16
CVE-2022-20531 [MEDIUM] CVE-2022-20531: In Telecom, there is a possible way to determine whether an app is installed, without query permissi
In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-15580P4MEDIUMCVSS 5.5v8.0v8.1+2 more2020-07-07
CVE-2020-15580 [MEDIUM] CVE-2020-15580: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attacke
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) by enrolling a new lock password. The Samsung ID is SVE-2020-17328 (July 2020).
nvd
CVE-2021-39664P4MEDIUMCVSS 5.5v12.0vAndroid-122022-02-11
CVE-2021-39664 [MEDIUM] CWE-125 CVE-2021-39664: In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bo
In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure when parsing an APK file with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-203938029
nvd
CVE-2020-0497P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0497 [MEDIUM] CWE-862 CVE-2020-0497: In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to
In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158481661
nvd
CVE-2020-0477P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-15
CVE-2020-0477 [MEDIUM] CWE-862 CVE-2020-0477: In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information dis
In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the current network configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And
nvd
CVE-2022-20458P4MEDIUMCVSS 5.5v12.1vAndroid-12L2023-01-26
CVE-2022-20458 [MEDIUM] CWE-532 CVE-2022-20458: The logs of sensitive information (PII) or hardware identifier should only be printed in Android "us
The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the StatusBarNotification.getKey() directly in logs, which could contain user's account name (i.e. PII),
nvd
CVE-2022-20042P4MEDIUMCVSS 5.5v8.1v9.0+3 more2022-02-09
CVE-2022-20042 [MEDIUM] CWE-755 CVE-2022-20042: In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could
In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108487; Issue ID: ALPS06108487.
nvd
CVE-2022-27822P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-04-11
CVE-2022-27822 [MEDIUM] CWE-284 CVE-2022-27822: Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows
Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.
nvd
CVE-2021-39765P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39765 [MEDIUM] CWE-610 CVE-2021-39765: In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local
In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535427
nvd