cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 273 of 339
CVE-2022-20285P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20285 [MEDIUM] CVE-2022-20285: In PackageManager, there is a possible way to determine whether an app is installed, without query p In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230868108
nvd
CVE-2022-20324P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20324 [MEDIUM] CWE-203 CVE-2022-20324: In Framework, there is a possible way to determine whether an app is installed, without query permis In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187042
nvd
CVE-2022-20129P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-06-15
CVE-2022-20129 [MEDIUM] CWE-20 CVE-2022-20129: In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user f In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 A
nvd
CVE-2022-20355P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-08-10
CVE-2022-20355 [MEDIUM] CWE-20 CVE-2022-20355: In get of PacProxyService.java, there is a possible system service crash due to improper input valid In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-219498290
nvd
CVE-2023-21103P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-21103 [MEDIUM] CWE-209 CVE-2023-21103: In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-259064622
nvd
CVE-2023-21268P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21268 [MEDIUM] CWE-22 CVE-2023-21268: In update of MmsProvider.java, there is a possible way to change directory permissions due to a path In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48550P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-09-04
CVE-2025-48550 [MEDIUM] CWE-22 CVE-2025-48550: In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of servic In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20112P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-05-10
CVE-2022-20112 [MEDIUM] CWE-269 CVE-2022-20112: In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 And
nvd
CVE-2022-20322P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20322 [MEDIUM] CWE-862 CVE-2022-20322: In PackageManager, there is a possible installed package disclosure due to a missing permission chec In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187176993
nvd
CVE-2023-42742P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42742 [MEDIUM] CWE-862 CVE-2023-42742: In sysui, there is a possible missing permission check. This could lead to local denial of service w In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-42744P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-12-04
CVE-2023-42744 [MEDIUM] CWE-862 CVE-2023-42744: In telecom service, there is a possible missing permission check. This could lead to local denial of In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-21300P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21300 [MEDIUM] CWE-203 CVE-2023-21300: In PackageManager, there is a possible way to determine whether an app is installed, without query p In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21303P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21303 [MEDIUM] CWE-203 CVE-2023-21303: In Content, here is a possible way to determine whether an app is installed, without query permissio In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-47340P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-05-09
CVE-2022-47340 [MEDIUM] CWE-787 CVE-2022-47340: In h265 codec firmware, there is a possible out of bounds write due to a missing bounds check. This In h265 codec firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges.
nvd
CVE-2023-21087P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-21087 [MEDIUM] CWE-248 CVE-2023-21087: In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. T In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261723753
nvd
CVE-2022-20326P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20326 [MEDIUM] CWE-862 CVE-2022-20326: In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. T In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-185235527
nvd
CVE-2022-20284P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20284 [MEDIUM] CWE-862 CVE-2022-20284: In Telephony, there is a possible information disclosure due to a missing permission check. This cou In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone accounts with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231986341
nvd
CVE-2023-21305P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21305 [MEDIUM] CWE-203 CVE-2023-21305: In Content, there is a possible way to determine whether an app is installed, without query permissi In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21026P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-21026 [MEDIUM] CWE-703 CVE-2023-21026: In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable regio In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID
nvd
CVE-2023-21033P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-21033 [MEDIUM] CWE-400 CVE-2023-21033: In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resour In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244713323
nvd
Google Android vulnerabilities | cvebase