Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 269 of 339
CVE-2018-9511P4MEDIUMCVSS 5.5v9.02018-10-02
CVE-2018-9511 [MEDIUM] CWE-909 CVE-2018-9511: In ipSecSetEncapSocketOwner of XfrmController.cpp, there is a possible failure to initialize a secur
In ipSecSetEncapSocketOwner of XfrmController.cpp, there is a possible failure to initialize a security feature due to uninitialized data. This could lead to local denial of service of IPsec on sockets with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-9.0 Android ID: A-1
nvd
CVE-2021-39670P4MEDIUMCVSS 5.5v12.0v12.1+1 more2022-05-10
CVE-2021-39670 [MEDIUM] CWE-770 CVE-2021-39670: In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to impro
In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-204087139
nvd
CVE-2019-1998P4MEDIUMCVSS 5.5v9.02019-02-28
CVE-2019-1998 [MEDIUM] CVE-2019-1998: In event_handler of keymaster_app.c, there is possible resource exhaustion due to a table being lost
In event_handler of keymaster_app.c, there is possible resource exhaustion due to a table being lost on reboot. This could lead to local denial of service that is not fixed by a factory reset, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116055338.
nvd
CVE-2022-20499P4MEDIUMCVSS 5.5v12.0v12.1+2 more2023-03-24
CVE-2022-20499 [MEDIUM] CVE-2022-20499: In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored config
In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-246539931
nvd
CVE-2020-0464P4MEDIUMCVSS 5.5v10.0vAndroid-102020-12-14
CVE-2020-0464 [MEDIUM] CWE-203 CVE-2020-0464: In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. Th
In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150371903
nvd
CVE-2020-0313P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0313 [MEDIUM] CVE-2020-0313: In NotificationManagerService, there is a possible permission bypass due to an unsafe PendingIntent.
In NotificationManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154917989
nvd
CVE-2022-20476P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-12-13
CVE-2022-20476 [MEDIUM] CWE-835 CVE-2022-20476: In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infin
In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2021-0321P4MEDIUMCVSS 5.5v11.0vAndroid-112021-01-11
CVE-2021-0321 [MEDIUM] CWE-203 CVE-2021-0321: In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determ
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Androi
nvd
CVE-2020-0307P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0307 [MEDIUM] CVE-2020-0307: In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead t
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645867
nvd
CVE-2020-0302P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0302 [MEDIUM] CVE-2020-0302: In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead t
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151646375
nvd
CVE-2016-6708P4MEDIUMCVSS 5.5≤ 7.02016-11-25
CVE-2016-6708 [MEDIUM] CWE-254 CVE-2016-6708: An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local mal
An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypass of user interaction requirements for any developer or security setting modifications. Android ID: A-30693465.
nvd
CVE-2021-25415P4MEDIUMCVSS 5.5v10.0v11.02021-06-11
CVE-2021-25415 [MEDIUM] CWE-94 CVE-2021-25415: Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 a
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.
nvd
CVE-2020-0269P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0269 [MEDIUM] CVE-2020-0269: In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This
In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645626
nvd
CVE-2020-25047P4MEDIUMCVSS 5.5v9.0v10.02020-08-31
CVE-2020-25047 [MEDIUM] CVE-2020-25047: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and Ind
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software. The S Secure application does not enforce the intended password requirement for a locked application. The Samsung IDs are SVE-2020-16746, SVE-2020-16764 (August 2020).
nvd
CVE-2020-0310P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0310 [MEDIUM] CVE-2020-0310: In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead t
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153356468
nvd
CVE-2021-0444P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-04-13
CVE-2021-0444 [MEDIUM] CVE-2021-0444: In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This
In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local information disclosure of contact data with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-178825358
nvd
CVE-2021-0338P4MEDIUMCVSS 5.5v10.0v11.0+1 more2021-02-10
CVE-2021-0338 [MEDIUM] CWE-770 CVE-2021-0338: In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds c
In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-156260178
nvd
CVE-2020-0311P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0311 [MEDIUM] CVE-2020-0311: In InputManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This c
In InputManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153878642
nvd
CVE-2020-0315P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0315 [MEDIUM] CVE-2020-0315: In Zen Mode, there is a possible permission bypass due to an unsafe PendingIntent. This could lead t
In Zen Mode, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155642026
nvd
CVE-2020-0331P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0331 [MEDIUM] CVE-2020-0331: In Settings, there is a possible permissions bypass. This could lead to local information disclosure
In Settings, there is a possible permissions bypass. This could lead to local information disclosure of the device's IMEI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147309310
nvd