Google Android vulnerabilities
7,234 known vulnerabilities affecting google/android.
Total CVEs
7,234
CISA KEV
18
actively exploited
Public exploits
52
Exploited in wild
18
Severity breakdown
CRITICAL544HIGH2984MEDIUM3458LOW248
Vulnerabilities
Page 27 of 362
CVE-2024-49744HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-49744 [HIGH] CWE-276 CVE-2024-49744: In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
cvelistv5nvd
CVE-2024-49734HIGHCVSS 7.5v14.0v15.0+2 more2025-01-21
CVE-2024-49734 [HIGH] CWE-200 CVE-2024-49734: In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determi
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-49735HIGHCVSS 7.8v15.0v152025-01-21
CVE-2024-49735 [HIGH] CWE-276 CVE-2024-49735: In multiple locations, there is a possible failure to persist permissions settings due to resource e
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-43096HIGHCVSS 8.8v12.0v12.1+8 more2025-01-21
CVE-2024-43096 [HIGH] CWE-787 CVE-2024-43096: In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing boun
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-43095HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-43095 [HIGH] CWE-203 CVE-2024-43095: In multiple locations, there is a possible way to obtain any system permission due to a logic error
In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
cvelistv5nvd
CVE-2024-43765HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-43765 [HIGH] CWE-276 CVE-2024-43765: In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/over
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
cvelistv5nvd
CVE-2024-43763MEDIUMCVSS 6.5v12.0v12.1+8 more2025-01-21
CVE-2024-43763 [MEDIUM] CWE-400 CVE-2024-43763: In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in
In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-49736MEDIUMCVSS 5.5v12.0v12.1+6 more2025-01-21
CVE-2024-49736 [MEDIUM] CWE-783 CVE-2024-49736: In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-49733MEDIUMCVSS 5.5v12.0v12.1+8 more2025-01-21
CVE-2024-49733 [MEDIUM] CWE-200 CVE-2024-49733: In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS f
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2023-40108MEDIUMCVSS 5.5v12.0v12.1+6 more2025-01-21
CVE-2023-40108 [MEDIUM] CWE-200 CVE-2023-40108: In multiple locations, there is a possible way to access media content belonging to another user due
In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9461HIGHCVSS 7.0v6.0v6.0.1+6 more2025-01-18
CVE-2018-9461 [HIGH] CWE-362 CVE-2018-9461: In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in
In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9464HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9464 [HIGH] CWE-125 CVE-2018-9464: In multiple locations, there is a possible way to read protected files due to a missing permission c
In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9389HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9389 [HIGH] CWE-787 CVE-2018-9389: In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap
In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9387HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9387 [HIGH] CWE-120 CVE-2018-9387: In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an inte
In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9401HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9401 [HIGH] CWE-276 CVE-2018-9401: In many locations, there is a possible way to access kernel memory in user space due to an incorrect
In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9406MEDIUMCVSS 5.5vAndroid Kernel2025-01-18
CVE-2018-9406 [MEDIUM] CWE-862 CVE-2018-9406: In NlpService, there is a possible way to obtain location information due to a missing permission ch
In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9405MEDIUMCVSS 6.7vAndroid Kernel2025-01-18
CVE-2018-9405 [MEDIUM] CWE-787 CVE-2018-9405: In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing b
In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2017-13322CRITICALCVSS 10.0v6.0v6.0.1+6 more2025-01-17
CVE-2017-13322 [CRITICAL] CWE-783 CVE-2017-13322: In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9375HIGHCVSS 7.8v6.0v6.0.1+6 more2025-01-17
CVE-2018-9375 [HIGH] CWE-269 CVE-2018-9375: In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete word
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2018-9382HIGHCVSS 7.8v6.0v6.0.1+4 more2025-01-17
CVE-2018-9382 [HIGH] CWE-862 CVE-2018-9382: In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot fro
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd