Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 261 of 339
CVE-2023-20999P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20999 [MEDIUM] CWE-835 CVE-2023-20999: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper i
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246750467
nvd
CVE-2023-20998P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20998 [MEDIUM] CWE-835 CVE-2023-20998: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper i
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246749936
nvd
CVE-2023-20996P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20996 [MEDIUM] CWE-835 CVE-2023-20996: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper i
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246749764
nvd
CVE-2023-20997P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20997 [MEDIUM] CWE-835 CVE-2023-20997: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper i
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246749702
nvd
CVE-2022-20230P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-07-13
CVE-2022-20230 [MEDIUM] CWE-116 CVE-2022-20230: In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due
In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID:
nvd
CVE-2018-9447P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2025-01-17
CVE-2018-9447 [MEDIUM] CWE-400 CVE-2018-9447: In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21299P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21299 [MEDIUM] CWE-203 CVE-2023-21299: In Package Manager, there is a possible way to determine whether an app is installed, without query
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21240P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-07-13
CVE-2023-21240 [MEDIUM] CWE-400 CVE-2023-21240: In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20929P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20929 [MEDIUM] CVE-2023-20929: In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby B
In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-23444270
nvd
CVE-2023-21167P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21167 [MEDIUM] CWE-119 CVE-2023-21167: In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI
In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259942964
nvd
CVE-2023-20703P4MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20703 [MEDIUM] CWE-125 CVE-2023-20703: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767853; Issue ID: ALPS07767853.
nvd
CVE-2023-20704P4MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20704 [MEDIUM] CWE-20 CVE-2023-20704: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.
nvd
CVE-2023-20706P4MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20706 [MEDIUM] CWE-125 CVE-2023-20706: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.
nvd
CVE-2023-20705P4MEDIUMCVSS 5.5v12.0v13.02023-05-15
CVE-2023-20705 [MEDIUM] CWE-20 CVE-2023-20705: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.
nvd
CVE-2022-20299P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20299 [MEDIUM] CWE-862 CVE-2022-20299: In ContentService, there is a possible way to check if the given account exists on the device due to
In ContentService, there is a possible way to check if the given account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201415895
nvd
CVE-2022-20298P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20298 [MEDIUM] CWE-862 CVE-2022-20298: In ContentService, there is a possible way to check if an account exists on the device due to a miss
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201416182
nvd
CVE-2022-20296P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20296 [MEDIUM] CWE-862 CVE-2022-20296: In ContentService, there is a possible way to check if an account exists on the device due to a miss
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201794303
nvd
CVE-2022-20303P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20303 [MEDIUM] CWE-862 CVE-2022-20303: In ContentService, there is a possible way to determine if an account is on the device without GET_A
In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200573021
nvd
CVE-2022-20301P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20301 [MEDIUM] CWE-862 CVE-2022-20301: In Content, there is a possible way to check if an account exists on the device due to a missing per
In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200956614
nvd
CVE-2022-20263P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20263 [MEDIUM] CWE-862 CVE-2022-20263: In ActivityManager, there is a way to read process state for other users due to a missing permission
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-217935264
nvd