Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 272 of 339
CVE-2021-39791P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39791 [MEDIUM] CWE-203 CVE-2021-39791: In WallpaperManagerService, there is a possible way to determine whether an app is installed, withou
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndro
nvd
CVE-2021-39766P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39766 [MEDIUM] CWE-203 CVE-2021-39766: In Settings, there is a possible way to determine whether an app is installed, without query permiss
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-198296
nvd
CVE-2021-39745P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39745 [MEDIUM] CWE-203 CVE-2021-39745: In DevicePolicyManager, there is a possible way to determine whether an app is installed, without qu
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid I
nvd
CVE-2021-39755P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39755 [MEDIUM] CWE-203 CVE-2021-39755: In DevicePolicyManager, there is a possible way to reveal the existence of an installed package with
In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-
nvd
CVE-2021-39744P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39744 [MEDIUM] CWE-203 CVE-2021-39744: In DevicePolicyManager, there is a possible way to determine whether an app is installed, without qu
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid I
nvd
CVE-2021-39760P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39760 [MEDIUM] CWE-203 CVE-2021-39760: In AudioService, there is a possible way to determine whether an app is installed, without query per
In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-19
nvd
CVE-2021-25357P4MEDIUMCVSS 5.5v8.1v9.02021-04-09
CVE-2021-25357 [MEDIUM] CWE-200 CVE-2021-25357: A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact information.
nvd
CVE-2021-30161P4MEDIUMCVSS 5.5v11.02021-04-06
CVE-2021-30161 [MEDIUM] CVE-2021-30161: An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the l
An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection mechanism after an incoming call has been terminated. The LG ID is LVE-SMP-210002 (April 2021).
nvd
CVE-2021-25453P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-09-09
CVE-2021-25453 [MEDIUM] CWE-20 CVE-2021-25453: Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted appl
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
nvd
CVE-2024-0027P4MEDIUMCVSS 5.5v12.0v12.1+6 more2024-05-07
CVE-2024-0027 [MEDIUM] CWE-770 CVE-2024-0027: In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to reso
In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-25392P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-06-11
CVE-2021-25392 [MEDIUM] CWE-200 CVE-2021-25392: Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allo
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.
nvd
CVE-2021-39770P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39770 [MEDIUM] CWE-276 CVE-2021-39770: In Framework, there is a possible disclosure of the device owner package due to a missing permission
In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-193033501
nvd
CVE-2022-48464P4MEDIUMCVSS 5.5v10.02023-12-04
CVE-2022-48464 [MEDIUM] CWE-787 CVE-2022-48464: In wifi service, there is a possible out of bounds write due to a missing bounds check. This could l
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48463P4MEDIUMCVSS 5.5v10.02023-12-04
CVE-2022-48463 [MEDIUM] CWE-787 CVE-2022-48463: In wifi service, there is a possible out of bounds write due to a missing bounds check. This could l
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-42719P4MEDIUMCVSS 5.5v12.02023-12-04
CVE-2023-42719 [MEDIUM] CWE-125 CVE-2023-42719: In video service, there is a possible out of bounds read due to a incorrect bounds check. This could
In video service, there is a possible out of bounds read due to a incorrect bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48462P4MEDIUMCVSS 5.5v10.02023-12-04
CVE-2022-48462 [MEDIUM] CWE-787 CVE-2022-48462: In wifi service, there is a possible out of bounds write due to a missing bounds check. This could l
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-42720P4MEDIUMCVSS 5.5v11.02023-12-04
CVE-2023-42720 [MEDIUM] CWE-125 CVE-2023-42720: In video service, there is a possible out of bounds read due to a missing bounds check. This could l
In video service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-42723P4MEDIUMCVSS 5.5v11.02023-12-04
CVE-2023-42723 [MEDIUM] CWE-125 CVE-2023-42723: In camera service, there is a possible out of bounds read due to a missing bounds check. This could
In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-42721P4MEDIUMCVSS 5.5v11.02023-12-04
CVE-2023-42721 [MEDIUM] CVE-2023-42721: In flv extractor, there is a possible missing verification incorrect input. This could lead to local
In flv extractor, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-42728P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42728 [MEDIUM] CWE-125 CVE-2023-42728: In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This coul
In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd