cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 259 of 339
CVE-2021-0986P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-0986 [MEDIUM] CWE-862 CVE-2021-0986: In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure a In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device admin due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi
nvd
CVE-2021-0415P4MEDIUMCVSS 5.5v10.0v11.02021-08-18
CVE-2021-0415 [MEDIUM] CWE-862 CVE-2021-0415: In memory management driver, there is a possible information disclosure due to a missing permission In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336692.
nvd
CVE-2021-0572P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0572 [MEDIUM] CWE-732 CVE-2021-0572: In doNotification of AccountManagerService.java, there is a possible permission bypass due to an uns In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-177931355
nvd
CVE-2021-0552P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0552 [MEDIUM] CWE-732 CVE-2021-0552: In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an u In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-175124820
nvd
CVE-2021-39757P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39757 [MEDIUM] CVE-2021-39757: In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-176094662
nvd
CVE-2021-25488P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-10-06
CVE-2021-25488 [MEDIUM] CWE-125 CVE-2021-25488: Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.
nvd
CVE-2021-0686P4MEDIUMCVSS 5.5v10.0v11.0+1 more2021-10-06
CVE-2021-0686 [MEDIUM] CWE-862 CVE-2021-0686: In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2021-0641P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-08-17
CVE-2021-0641 [MEDIUM] CWE-862 CVE-2021-0641: In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure o In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Andro
nvd
CVE-2021-0554P4MEDIUMCVSS 5.5v11.0vAndroid-112021-06-22
CVE-2021-0554 [MEDIUM] CWE-862 CVE-2021-0554: In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This cou In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158482162
nvd
CVE-2023-21136P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-06-15
CVE-2023-21136 [MEDIUM] CWE-20 CVE-2023-21136: In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to i In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-246
nvd
CVE-2021-39777P4MEDIUMCVSS 5.5v12.0vAndroid-12L2022-03-30
CVE-2021-39777 [MEDIUM] CWE-668 CVE-2021-39777: In Telephony, there is a possible way to determine whether an app is installed, without query permis In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-194743207
nvd
CVE-2023-21252P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-10-06
CVE-2023-21252 [MEDIUM] CVE-2023-21252: In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-22291P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-02-11
CVE-2022-22291 [MEDIUM] CWE-779 CVE-2022-22291: Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileg Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.
nvd
CVE-2024-31314P4MEDIUMCVSS 5.5v12.0v12.1+6 more2024-07-09
CVE-2024-31314 [MEDIUM] CWE-770 CVE-2024-31314: In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource ex In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20466P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-12-13
CVE-2022-20466 [MEDIUM] CWE-1188 CVE-2022-20466: In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to obse In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: And
nvd
CVE-2021-1010P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1010 [MEDIUM] CWE-862 CVE-2021-1010: In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could l In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189857801
nvd
CVE-2021-1025P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1025 [MEDIUM] CWE-862 CVE-2021-1025: In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether a In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A
nvd
CVE-2021-1011P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1011 [MEDIUM] CWE-862 CVE-2021-1011: In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This c In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-188219307
nvd
CVE-2022-20200P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-06-15
CVE-2022-20200 [MEDIUM] CWE-862 CVE-2022-20200: In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing p In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-212695058
nvd
CVE-2022-20206P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-06-15
CVE-2022-20206 [MEDIUM] CWE-862 CVE-2022-20206: In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission ch In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220737634
nvd
Google Android vulnerabilities | cvebase