cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 258 of 339
CVE-2019-9475P4MEDIUMCVSS 5.5v10.0vAndroid 102021-06-11
CVE-2019-9475 [MEDIUM] CWE-668 CVE-2019-9475: In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions byp In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-9496886
nvd
CVE-2022-20199P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20199 [MEDIUM] CWE-610 CVE-2022-20199: In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confus In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-199291025
nvd
CVE-2022-20552P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20552 [MEDIUM] CWE-416 CVE-2022-20552: In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-243922806
nvd
CVE-2021-0518P4MEDIUMCVSS 5.5v13.0vAndroid-132021-07-14
CVE-2021-0518 [MEDIUM] CWE-862 CVE-2021-0518: In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. Thi In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-176541017
nvd
CVE-2021-0408P4MEDIUMCVSS 5.5v10.0v11.02021-08-18
CVE-2021-0408 [MEDIUM] CWE-125 CVE-2021-0408: In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This coul In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489195; Issue ID: ALPS05489220.
nvd
CVE-2019-9268P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9268 [MEDIUM] CWE-416 CVE-2019-9268: In libstagefright, there is a possible use-after-free due to improper locking. This could lead to lo In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-77474014
nvd
CVE-2021-0542P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0542 [MEDIUM] CWE-668 CVE-2021-0542: In updateNotification of BeamTransferManager.java, there is a missing permission check. This could l In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168712890
nvd
CVE-2021-0381P4MEDIUMCVSS 5.5v11.0vAndroid-112021-03-10
CVE-2021-0381 [MEDIUM] CWE-276 CVE-2021-0381: In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass du In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153466381
nvd
CVE-2019-2119P4MEDIUMCVSS 5.5v8.0v8.1+2 more2019-07-08
CVE-2019-2119 [MEDIUM] CWE-667 CVE-2019-2119: In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to im In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID:
nvd
CVE-2022-20019P4MEDIUMCVSS 5.5v10.0v11.02022-01-04
CVE-2022-20019 [MEDIUM] CWE-20 CVE-2022-20019: In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. Thi In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917620; Issue ID: ALPS05917620.
nvd
CVE-2022-20020P4MEDIUMCVSS 5.5v11.02022-01-04
CVE-2022-20020 [MEDIUM] CWE-20 CVE-2022-20020: In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This coul In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05943906; Issue ID: ALPS05943906.
nvd
CVE-2021-0382P4MEDIUMCVSS 5.5v11.0vAndroid-112021-03-10
CVE-2021-0382 [MEDIUM] CWE-863 CVE-2021-0382: In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140727941
nvd
CVE-2022-20510P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20510 [MEDIUM] CWE-862 CVE-2022-20510: In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the notification streaming policy of other users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi
nvd
CVE-2021-39700P4MEDIUMCVSS 5.5v10.0v11.0+2 more2022-05-10
CVE-2021-39700 [MEDIUM] CVE-2021-39700: In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to rep In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201645790
nvd
CVE-2021-0410P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0410 [MEDIUM] CWE-125 CVE-2021-0410: In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This coul In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561360; Issue ID: ALPS05561360.
nvd
CVE-2021-0409P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0409 [MEDIUM] CWE-125 CVE-2021-0409: In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This coul In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561359; Issue ID: ALPS05561359.
nvd
CVE-2021-0614P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0614 [MEDIUM] CWE-125 CVE-2021-0614: In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This coul In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05495528; Issue ID: ALPS05495528.
nvd
CVE-2021-0613P4MEDIUMCVSS 5.5v10.0v11.02021-10-25
CVE-2021-0613 [MEDIUM] CWE-125 CVE-2021-0613: In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This coul In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05489178.
nvd
CVE-2021-0521P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-06-21
CVE-2021-0521 [MEDIUM] CWE-862 CVE-2021-0521: In getAllPackages of PackageManagerService, there is a possible information disclosure due to a miss In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of cross-user permissions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 An
nvd
CVE-2021-39631P4MEDIUMCVSS 5.5v10.0v11.0+2 more2022-02-11
CVE-2021-39631 [MEDIUM] CVE-2021-39631: In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functional In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wrong security/privacy expectations due to a misleading message. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-
nvd
Google Android vulnerabilities | cvebase