Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 274 of 339
CVE-2022-20426P4MEDIUMCVSS 5.5v10.0v11.0+4 more2022-11-08
CVE-2022-20426 [MEDIUM] CWE-754 CVE-2022-20426: In multiple functions of many files, there is a possible obstruction of the user's ability to select
In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-
nvd
CVE-2023-21320P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21320 [MEDIUM] CWE-203 CVE-2023-21320: In Device Policy, there is a possible way to verify if a particular admin app is registered on the d
In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21317P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21317 [MEDIUM] CWE-203 CVE-2023-21317: In ContentService, there is a possible way to determine whether an app is installed, without query p
In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21177P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21177 [MEDIUM] CWE-862 CVE-2023-21177: In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the ap
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android
nvd
CVE-2022-38685P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-05-09
CVE-2022-38685 [MEDIUM] CWE-862 CVE-2022-38685: In bluetooth service, there is a possible missing permission check. This could lead to local denial
In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.
nvd
CVE-2023-21318P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21318 [MEDIUM] CWE-203 CVE-2023-21318: In Content, there is a possible way to determine whether an app is installed, without query permissi
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21316P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21316 [MEDIUM] CWE-203 CVE-2023-21316: In Content, there is a possible way to determine whether an app is installed, without query permissi
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20962P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20962 [MEDIUM] CWE-926 CVE-2023-20962: In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foregro
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Androi
nvd
CVE-2023-21364P4MEDIUMCVSS 5.5fixed in 14.0v14.0+1 more2023-10-30
CVE-2023-21364 [MEDIUM] CVE-2023-21364: In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to l
In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21280P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-08-14
CVE-2023-21280 [MEDIUM] CWE-400 CVE-2023-21280: In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due
In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20930P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-05-15
CVE-2023-20930 [MEDIUM] CWE-400 CVE-2023-20930: In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boo
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android
nvd
CVE-2022-30727P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-06-07
CVE-2022-30727 [MEDIUM] CWE-280 CVE-2022-30727: Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in Perso
Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.
nvd
CVE-2022-42754P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42754 [MEDIUM] CWE-416 CVE-2022-42754: In npu driver, there is a memory corruption due to a use after free. This could lead to local denial
In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.
nvd
CVE-2023-42653P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-11-01
CVE-2023-42653 [MEDIUM] CWE-787 CVE-2023-42653: In faceid service, there is a possible out of bounds write due to a missing bounds check. This could
In faceid service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-52347P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-04-08
CVE-2023-52347 [MEDIUM] CWE-787 CVE-2023-52347: In ril service, there is a possible out of bounds write due to a missing bounds check. This could le
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2018-9412P4MEDIUMCVSS 5.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9412 [MEDIUM] CWE-400 CVE-2018-9412: In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input
In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-48345P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48345 [MEDIUM] CWE-125 CVE-2023-48345: In video decoder, there is a possible out of bounds read due to improper input validation. This coul
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48341P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48341 [MEDIUM] CWE-125 CVE-2023-48341: In video decoder, there is a possible out of bounds read due to improper input validation. This coul
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48346P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48346 [MEDIUM] CWE-20 CVE-2023-48346: In video decoder, there is a possible improper input validation. This could lead to local denial of
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48344P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48344 [MEDIUM] CWE-125 CVE-2023-48344: In video decoder, there is a possible out of bounds read due to improper input validation. This coul
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd