Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 270 of 339
CVE-2020-0295P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0295 [MEDIUM] CVE-2020-0295: In Telecom, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to
In Telecom, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155650969
nvd
CVE-2020-0304P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0304 [MEDIUM] CVE-2020-0304: In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead t
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645695
nvd
CVE-2020-0312P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0312 [MEDIUM] CVE-2020-0312: In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could l
In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153879099
nvd
CVE-2023-21253P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-10-06
CVE-2023-21253 [MEDIUM] CWE-400 CVE-2023-21253: In multiple locations, there is a possible way to crash multiple system services due to resource exh
In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0274P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-17
CVE-2020-0274 [MEDIUM] CVE-2020-0274: In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This co
In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-120781925
nvd
CVE-2020-0134P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0134 [MEDIUM] CWE-909 CVE-2020-0134: In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized da
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146052771
nvd
CVE-2019-9369P4MEDIUMCVSS 5.5v10.0vAndroid-102019-09-27
CVE-2019-9369 [MEDIUM] CWE-908 CVE-2019-9369: In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclos
In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79995407
nvd
CVE-2023-40074P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-12-04
CVE-2023-40074 [MEDIUM] CVE-2023-40074: In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of servic
In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-9376P4MEDIUMCVSS 5.5v8.0v8.1+4 more2019-09-27
CVE-2019-9376 [MEDIUM] CWE-834 CVE-2019-9376: In Account of Account.java, there is a possible boot loop due to improper input validation. This cou
In Account of Account.java, there is a possible boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android; Versions: Android-9, Android-8.0, Android-8.1; Android ID: A-129287265.
nvd
CVE-2021-39690P4MEDIUMCVSS 5.5v12.0vAndroid-122022-03-16
CVE-2021-39690 [MEDIUM] CWE-1284 CVE-2021-39690: In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-204316511
nvd
CVE-2019-20784P4MEDIUMCVSS 5.5v7.0v7.1+3 more2020-04-17
CVE-2019-20784 [MEDIUM] CVE-2019-20784: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipse
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipsets) software. Interaction of GPS with 911 emergency calls is mishandled. The LG ID is LVE-SMP-180012 (January 2019).
nvd
CVE-2020-10846P4MEDIUMCVSS 5.5v9.0v10.02020-03-24
CVE-2020-10846 [MEDIUM] CWE-287 CVE-2020-10846: An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can en
An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (February 2020).
nvd
CVE-2019-20550P4MEDIUMCVSS 5.5v8.0v8.12020-03-24
CVE-2019-20550 [MEDIUM] CWE-306 CVE-2019-20550: An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software
An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).
nvd
CVE-2022-20414P4MEDIUMCVSS 5.5v10.0v11.0+4 more2022-11-08
CVE-2022-20414 [MEDIUM] CWE-755 CVE-2022-20414: In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Andr
nvd
CVE-2023-20922P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-01-26
CVE-2023-20922 [MEDIUM] CWE-400 CVE-2023-20922: In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaus
In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-237291548
nvd
CVE-2021-0702P4MEDIUMCVSS 5.5v11.0vAndroid-112021-10-22
CVE-2021-0702 [MEDIUM] CVE-2021-0702: In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unin
In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore downgrade. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-193932765
nvd
CVE-2022-39897P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-08
CVE-2022-39897 [MEDIUM] CWE-200 CVE-2022-39897: Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows att
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.
nvd
CVE-2022-20538P4MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20538 [MEDIUM] CWE-203 CVE-2022-20538: In getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is inst
In getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: And
nvd
CVE-2021-25459P4MEDIUMCVSS 5.5v10.0v11.02021-09-09
CVE-2021-25459 [MEDIUM] CWE-285 CVE-2021-25459: An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 R
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
nvd
CVE-2022-20317P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20317 [MEDIUM] CVE-2022-20317: In SystemUI, there is a possible way to unexpectedly enable the external speaker due to a logic erro
In SystemUI, there is a possible way to unexpectedly enable the external speaker due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-190199063
nvd