Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 282 of 339
CVE-2022-39129P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-39129 [MEDIUM] CWE-121 CVE-2022-39129: In face detect driver, there is a possible out of bounds write due to a missing bounds check. This c
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
nvd
CVE-2022-39132P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-39132 [MEDIUM] CWE-126 CVE-2022-39132: In camera driver, there is a possible out of bounds write due to a missing bounds check. This could
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
nvd
CVE-2022-38679P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38679 [MEDIUM] CWE-400 CVE-2022-38679: In music service, there is a missing permission check. This could lead to local denial of service in
In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed.
nvd
CVE-2022-39115P4MEDIUMCVSS 5.5v10.0v11.02022-10-14
CVE-2022-39115 [MEDIUM] CWE-862 CVE-2022-39115: In Music service, there is a missing permission check. This could lead to local denial of service in
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
nvd
CVE-2021-0524P4MEDIUMCVSS 5.5v12.0vAndroid-122022-02-11
CVE-2021-0524 [MEDIUM] CWE-203 CVE-2021-0524: In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android I
nvd
CVE-2021-39659P4MEDIUMCVSS 5.5v10.0v11.0+2 more2022-01-14
CVE-2021-39659 [MEDIUM] CWE-755 CVE-2021-39659: In sortSimPhoneAccountsForEmergency of CreateConnectionProcessor.java, there is a possible preventio
In sortSimPhoneAccountsForEmergency of CreateConnectionProcessor.java, there is a possible prevention of access to emergency calling due to an unhandled exception. In rare instances, this could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 A
nvd
CVE-2021-0417P4MEDIUMCVSS 5.5v10.0v11.02021-08-18
CVE-2021-0417 [MEDIUM] CWE-20 CVE-2021-0417: In memory management driver, there is a possible system crash due to improper input validation. This
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336702.
nvd
CVE-2021-0416P4MEDIUMCVSS 5.5v10.0v11.02021-08-18
CVE-2021-0416 [MEDIUM] CWE-20 CVE-2021-0416: In memory management driver, there is a possible system crash due to improper input validation. This
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336700.
nvd
CVE-2021-0418P4MEDIUMCVSS 5.5v10.0v11.02021-08-18
CVE-2021-0418 [MEDIUM] CWE-20 CVE-2021-0418: In memory management driver, there is a possible system crash due to improper input validation. This
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336706.
nvd
CVE-2021-0419P4MEDIUMCVSS 5.5v10.0v11.02021-08-18
CVE-2021-0419 [MEDIUM] CWE-20 CVE-2021-0419: In memory management driver, there is a possible system crash due to improper input validation. This
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336713.
nvd
CVE-2021-39624P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-03-16
CVE-2021-39624 [MEDIUM] CVE-2021-39624: In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This
In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-67862680
nvd
CVE-2022-20051P4MEDIUMCVSS 5.5v11.0v12.02022-03-10
CVE-2022-20051 [MEDIUM] CWE-269 CVE-2022-20051: In ims service, there is a possible unexpected application behavior due to incorrect privilege assig
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219127; Issue ID: ALPS06219127.
nvd
CVE-2022-20260P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20260 [MEDIUM] CVE-2022-20260: In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to loca
In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-220865698
nvd
CVE-2022-20143P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-06-15
CVE-2022-20143 [MEDIUM] CWE-770 CVE-2022-20143: In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220735360
nvd
CVE-2022-20272P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20272 [MEDIUM] CWE-276 CVE-2022-20272: In PermissionController, there is a possible misunderstanding about the default SMS application's pe
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-207672568
nvd
CVE-2024-0026P4MEDIUMCVSS 5.5v12.0v12.1+6 more2024-05-07
CVE-2024-0026 [MEDIUM] CWE-770 CVE-2024-0026: In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to
In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20304P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20304 [MEDIUM] CWE-203 CVE-2022-20304: In Content, there is a possible way to determinate the user's account due to side channel informatio
In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-199751919
nvd
CVE-2022-48231P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-05-09
CVE-2022-48231 [MEDIUM] CWE-476 CVE-2022-48231: In soter service, there is a possible missing permission check. This could lead to local denial of s
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
nvd
CVE-2022-48241P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-05-09
CVE-2022-48241 [MEDIUM] CWE-476 CVE-2022-48241: In telephony service, there is a possible missing permission check. This could lead to local denial
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
nvd
CVE-2022-38675P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-38675 [MEDIUM] CWE-787 CVE-2022-38675: In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could le
In gpu driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
nvd