cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 285 of 339
CVE-2022-44422P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-01-04
CVE-2022-44422 [MEDIUM] CWE-862 CVE-2022-44422: In music service, there is a missing permission check. This could lead to local denial of service in In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
nvd
CVE-2022-48460P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-11-01
CVE-2022-48460 [MEDIUM] CVE-2022-48460: In setting service, there is a possible undefined behavior due to incorrect error handling. This cou In setting service, there is a possible undefined behavior due to incorrect error handling. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2022-48448P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-06-06
CVE-2022-48448 [MEDIUM] CWE-862 CVE-2022-48448: In telephony service, there is a possible missing permission check. This could lead to local denial In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
nvd
CVE-2023-38462P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38462 [MEDIUM] CWE-862 CVE-2023-38462: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-38446P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38446 [MEDIUM] CWE-862 CVE-2023-38446: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-38448P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38448 [MEDIUM] CWE-862 CVE-2023-38448: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-38463P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38463 [MEDIUM] CWE-862 CVE-2023-38463: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-38461P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38461 [MEDIUM] CWE-862 CVE-2023-38461: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-38447P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38447 [MEDIUM] CWE-862 CVE-2023-38447: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-38457P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38457 [MEDIUM] CWE-862 CVE-2023-38457: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2023-38445P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38445 [MEDIUM] CWE-862 CVE-2023-38445: In vowifiservice, there is a possible missing permission check.This could lead to local denial of se In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges
nvd
CVE-2022-48440P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-06-06
CVE-2022-48440 [MEDIUM] CWE-862 CVE-2022-48440: In dialer service, there is a possible missing permission check. This could lead to local denial of In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
nvd
CVE-2022-48441P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-06-06
CVE-2022-48441 [MEDIUM] CWE-862 CVE-2022-48441: In dialer service, there is a possible missing permission check. This could lead to local denial of In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
nvd
CVE-2022-48442P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-06-06
CVE-2022-48442 [MEDIUM] CWE-862 CVE-2022-48442: In dialer service, there is a possible missing permission check. This could lead to local denial of In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
nvd
CVE-2022-44420P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-05-09
CVE-2022-44420 [MEDIUM] CWE-345 CVE-2022-44420: In modem, there is a possible missing verification of HashMME value in Security Mode Command. This c In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges.
nvd
CVE-2015-8074P4MEDIUMCVSS 5.0≤ 5.12015-11-03
CVE-2015-8074 [MEDIUM] CVE-2015-8074: mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than CVE-2015-6611.
nvd
CVE-2021-25339P4MEDIUMCVSS 5.2v10.0v11.02021-03-04
CVE-2021-25339 [MEDIUM] CWE-20 CVE-2021-25339: Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corrupt EL2 memory.
nvd
CVE-2015-6622P4MEDIUMCVSS 5.0≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6622 [MEDIUM] CWE-200 CVE-2015-6622: The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attack The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23905002.
nvd
CVE-2015-6628P4MEDIUMCVSS 5.0≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6628 [MEDIUM] CWE-200 CVE-2015-6628: Media Framework in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain Media Framework in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24074485.
nvd
CVE-2024-56185P4MEDIUMCVSS 5.1vAndroid kernel2025-03-10
CVE-2024-56185 [MEDIUM] CWE-125 CVE-2024-56185: In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-o In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase