cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 280 of 339
CVE-2022-38683P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-01-04
CVE-2022-38683 [MEDIUM] CWE-862 CVE-2022-38683: In contacts service, there is a missing permission check. This could lead to local denial of service In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
nvd
CVE-2022-38678P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-01-04
CVE-2022-38678 [MEDIUM] CWE-862 CVE-2022-38678: In contacts service, there is a missing permission check. This could lead to local denial of service In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
nvd
CVE-2022-39104P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-01-04
CVE-2022-39104 [MEDIUM] CWE-862 CVE-2022-39104: In contacts service, there is a missing permission check. This could lead to local denial of service In contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service with no additional execution privileges needed.
nvd
CVE-2022-38684P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-01-04
CVE-2022-38684 [MEDIUM] CWE-862 CVE-2022-38684: In contacts service, there is a missing permission check. This could lead to local denial of service In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
nvd
CVE-2022-38682P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-01-04
CVE-2022-38682 [MEDIUM] CWE-862 CVE-2022-38682: In contacts service, there is a missing permission check. This could lead to local denial of service In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
nvd
CVE-2022-39113P4MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39113 [MEDIUM] CWE-862 CVE-2022-39113: In Music service, there is a missing permission check. This could lead to local denial of service in In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2022-39114P4MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39114 [MEDIUM] CWE-862 CVE-2022-39114: In Music service, there is a missing permission check. This could lead to local denial of service in In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2022-39112P4MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39112 [MEDIUM] CWE-862 CVE-2022-39112: In Music service, there is a missing permission check. This could lead to local denial of service in In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2020-0247P4MEDIUMCVSS 5.5v8.0v8.1+2 more2020-08-11
CVE-2020-0247 [MEDIUM] CWE-755 CVE-2020-0247: In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an unca In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1Android ID: A-156087409
nvd
CVE-2020-0318P4MEDIUMCVSS 5.5v11.0vAndroid-112020-09-18
CVE-2020-0318 [MEDIUM] CWE-755 CVE-2020-0318: In the System UI, there is a possible system crash due to an uncaught exception. This could lead to In the System UI, there is a possible system crash due to an uncaught exception. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-33646131
nvd
CVE-2020-0469P4MEDIUMCVSS 5.5v11.0vAndroid-112020-12-14
CVE-2020-0469 [MEDIUM] CVE-2020-0469: In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password du In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password due to logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168692734
nvd
CVE-2018-21076P4MEDIUMCVSS 5.5v7.0v7.1.0+2 more2020-04-08
CVE-2018-21076 [MEDIUM] CWE-200 CVE-2018-21076: An issue was discovered on Samsung mobile devices with N(7.x) (Exynos8890/8895 chipsets) software. T An issue was discovered on Samsung mobile devices with N(7.x) (Exynos8890/8895 chipsets) software. There is information disclosure (a KASLR offset) in the Secure Driver via a modified trustlet. The Samsung ID is SVE-2017-10987 (April 2018).
nvd
CVE-2019-20540P4MEDIUMCVSS 5.5v7.0v7.1.0+5 more2020-03-24
CVE-2019-20540 [MEDIUM] CWE-125 CVE-2019-20540: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a buffer over-read and possible information leak in the core touch screen driver. The Samsung ID is SVE-2019-14942 (November 2019).
nvd
CVE-2022-20425P4MEDIUMCVSS 5.5v10.0v11.0+4 more2022-10-11
CVE-2022-20425 [MEDIUM] CWE-400 CVE-2022-20425: In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performan In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android I
nvd
CVE-2020-0206P4MEDIUMCVSS 5.5v10.0vAndroid-102020-06-11
CVE-2020-0206 [MEDIUM] CWE-20 CVE-2020-0206: In the settings app, there is a possible app crash due to improper input validation. This could lead In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of service of the Settings app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136005061
nvd
CVE-2020-15577P4MEDIUMCVSS 5.5v9.0v10.02020-07-07
CVE-2020-15577 [MEDIUM] CVE-2020-15577: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Cameralyzer allo An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Cameralyzer allows attackers to write files to the SD card. The Samsung ID is SVE-2020-16830 (July 2020).
nvd
CVE-2019-20543P4MEDIUMCVSS 5.5v9.02020-03-24
CVE-2019-20543 [MEDIUM] CVE-2019-20543: An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via SamsungPay mini. The Samsung ID is SVE-2019-15090 (November 2019).
nvd
CVE-2021-3022P4MEDIUMCVSS 5.5v10.02021-01-05
CVE-2021-3022 [MEDIUM] CVE-2021-3022: An issue was discovered on LG mobile devices with Android OS 10 software. There was no write protect An issue was discovered on LG mobile devices with Android OS 10 software. There was no write protection for the MTK protect2 partition. The LG ID is LVE-SMP-200028 (January 2021).
nvd
CVE-2022-20500P4MEDIUMCVSS 5.5v10.0v11.0+4 more2022-12-13
CVE-2022-20500 [MEDIUM] CWE-755 CVE-2022-20500: In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught excepti In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-246540168
nvd
CVE-2023-20908P4MEDIUMCVSS 5.5v10.0v11.0+4 more2023-01-26
CVE-2023-20908 [MEDIUM] CWE-400 CVE-2023-20908: In several functions of SettingsState.java, there is a possible system crash loop due to resource ex In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-2394158
nvd
Google Android vulnerabilities | cvebase