Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 286 of 339
CVE-2019-9239P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9239 [MEDIUM] CWE-125 CVE-2019-9239: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121263487
nvd
CVE-2019-2039P4MEDIUMCVSS 5.0v7.0v7.1.1+4 more2019-04-19
CVE-2019-2039 [MEDIUM] CWE-125 CVE-2019-2039: In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds
In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. A
nvd
CVE-2019-9240P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9240 [MEDIUM] CWE-125 CVE-2019-9240: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121150966
nvd
CVE-2019-9236P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9236 [MEDIUM] CWE-125 CVE-2019-9236: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122322613
nvd
CVE-2019-9296P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9296 [MEDIUM] CWE-125 CVE-2019-9296: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112162089
nvd
CVE-2019-9235P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9235 [MEDIUM] CWE-125 CVE-2019-9235: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122323053
nvd
CVE-2019-9242P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9242 [MEDIUM] CWE-125 CVE-2019-9242: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121035878
nvd
CVE-2019-9246P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9246 [MEDIUM] CWE-125 CVE-2019-9246: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120428637
nvd
CVE-2019-9244P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9244 [MEDIUM] CWE-125 CVE-2019-9244: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120865977
nvd
CVE-2019-9356P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9356 [MEDIUM] CWE-125 CVE-2019-9356: In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead
In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111699773
nvd
CVE-2019-9251P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9251 [MEDIUM] CWE-125 CVE-2019-9251: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120274615
nvd
CVE-2019-9344P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9344 [MEDIUM] CWE-125 CVE-2019-9344: In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead
In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120845341
nvd
CVE-2019-9383P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9383 [MEDIUM] CWE-125 CVE-2019-9383: In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead
In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120843827
nvd
CVE-2019-9421P4MEDIUMCVSS 5.0v10.0vAndroid-102019-09-27
CVE-2019-9421 [MEDIUM] CWE-125 CVE-2019-9421: In libandroidfw, there is a possible OOB read due to an integer overflow. This could lead to local i
In libandroidfw, there is a possible OOB read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111215250
nvd
CVE-2021-0952P4MEDIUMCVSS 5.0v9.0v10.0+3 more2021-12-15
CVE-2021-0952 [MEDIUM] CVE-2021-0952: In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confuse
In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure of user's contacts with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-195748381
nvd
CVE-2021-0569P4MEDIUMCVSS 5.0v11.0vAndroid-112021-06-22
CVE-2021-0569 [MEDIUM] CWE-1021 CVE-2021-0569: In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/ov
In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174045870
nvd
CVE-2022-20394P4MEDIUMCVSS 5.0v10.0v11.0+3 more2022-10-11
CVE-2022-20394 [MEDIUM] CWE-862 CVE-2022-20394: In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to d
In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Androi
nvd
CVE-2015-6783P4MEDIUMCVSS 4.3v5.0v6.02015-12-06
CVE-2015-6783 [MEDIUM] CWE-20 CVE-2015-6783: The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linke
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive.
nvd
CVE-2019-2219P4MEDIUMCVSS 4.7v9.0v10.0+1 more2019-12-06
CVE-2019-2219 [MEDIUM] CWE-362 CVE-2019-2219: In several functions of NotificationManagerService.java and related files, there is a possible way t
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi
nvd
CVE-2021-0320P4MEDIUMCVSS 4.7v10.0v11.0+2 more2021-01-11
CVE-2021-0320 [MEDIUM] CWE-362 CVE-2021-0320: In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible b
In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions
nvd