Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 271 of 339
CVE-2022-20046P4MEDIUMCVSS 5.5v8.1v9.0+3 more2022-02-09
CVE-2022-20046 [MEDIUM] CWE-401 CVE-2022-20046: In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local d
In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS06142410.
nvd
CVE-2021-1030P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1030 [MEDIUM] CWE-203 CVE-2021-1030: In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-1014P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1014 [MEDIUM] CWE-203 CVE-2021-1014: In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine w
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A
nvd
CVE-2021-1005P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1005 [MEDIUM] CWE-203 CVE-2021-1005: In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whethe
In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi
nvd
CVE-2021-0997P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-0997 [MEDIUM] CWE-532 CVE-2021-0997: In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclos
In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191086488
nvd
CVE-2021-1026P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1026 [MEDIUM] CWE-203 CVE-2021-1026: In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is insta
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Androi
nvd
CVE-2021-1013P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1013 [MEDIUM] CWE-203 CVE-2021-1013: In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java,
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is n
nvd
CVE-2021-1009P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1009 [MEDIUM] CWE-203 CVE-2021-1009: In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine wh
In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An
nvd
CVE-2021-1012P4MEDIUMCVSS 5.5v12.0vAndroid-122021-12-15
CVE-2021-1012 [MEDIUM] CWE-203 CVE-2021-1012: In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app i
In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2021-0672P4MEDIUMCVSS 5.5v8.1v9.0+3 more2021-11-18
CVE-2021-0672 [MEDIUM] CWE-862 CVE-2021-0672: In Browser app, there is a possible information disclosure due to a missing permission check. This c
In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-199678035
nvd
CVE-2021-0424P4MEDIUMCVSS 5.5v10.0v11.02021-09-27
CVE-2021-0424 [MEDIUM] CWE-770 CVE-2021-0424: In memory management driver, there is a possible system crash due to a missing bounds check. This co
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05393787.
nvd
CVE-2021-0422P4MEDIUMCVSS 5.5v10.0v11.02021-09-27
CVE-2021-0422 [MEDIUM] CWE-770 CVE-2021-0422: In memory management driver, there is a possible system crash due to a missing bounds check. This co
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381071.
nvd
CVE-2021-0420P4MEDIUMCVSS 5.5v10.0v11.02021-08-18
CVE-2021-0420 [MEDIUM] CWE-770 CVE-2021-0420: In memory management driver, there is a possible system crash due to a missing bounds check. This co
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05381065.
nvd
CVE-2023-21243P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-07-13
CVE-2023-21243 [MEDIUM] CWE-120 CVE-2023-21243: In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the s
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-39754P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39754 [MEDIUM] CWE-203 CVE-2021-39754: In ContextImpl, there is a possible way to determine whether an app is installed, without query perm
In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:Android ID: A-207133709
nvd
CVE-2021-39756P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39756 [MEDIUM] CWE-203 CVE-2021-39756: In Framework, there is a possible way to determine whether an app is installed, without query permis
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-18435
nvd
CVE-2021-39775P4MEDIUMCVSS 5.5v12.0vAndroid-12L2022-03-30
CVE-2021-39775 [MEDIUM] CWE-203 CVE-2021-39775: In People, there is a possible way to determine whether an app is installed, without query permissio
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-20646585
nvd
CVE-2021-39761P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39761 [MEDIUM] CWE-203 CVE-2021-39761: In Media, there is a possible way to determine whether an app is installed, without query permission
In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-179783181
nvd
CVE-2021-39788P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39788 [MEDIUM] CWE-203 CVE-2021-39788: In TelecomManager, there is a possible way to check if a particular self managed phone account was r
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAn
nvd
CVE-2021-39773P4MEDIUMCVSS 5.5v12.0vAndroid-12L2022-03-30
CVE-2021-39773 [MEDIUM] CWE-203 CVE-2021-39773: In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel i
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-191276656
nvd