Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 290 of 339
CVE-2022-20215P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-01-26
CVE-2022-20215 [MEDIUM] CWE-1021 CVE-2022-20215: In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjackin
In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183794206
nvd
CVE-2022-20213P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-01-26
CVE-2022-20213 [MEDIUM] CWE-1021 CVE-2022-20213: In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/o
In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183410508
nvd
CVE-2021-25462P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-09-09
CVE-2021-25462 [MEDIUM] CWE-476 CVE-2021-25462: NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attacker
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
nvd
CVE-2021-25458P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-09-09
CVE-2021-25458 [MEDIUM] CWE-476 CVE-2021-25458: NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attacker
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
nvd
CVE-2021-1038P4MEDIUMCVSS 5.5v9.0v10.0+3 more2021-12-15
CVE-2021-1038 [MEDIUM] CWE-1021 CVE-2021-1038: In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay a
In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-183411279
nvd
CVE-2022-38690P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38690 [MEDIUM] CWE-119 CVE-2022-38690: In camera driver, there is a possible memory corruption due to improper locking. This could lead to
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
nvd
CVE-2022-20288P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20288 [MEDIUM] CVE-2022-20288: In AppSearchManagerService, there is a possible way to determine whether an app is installed, withou
In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-
nvd
CVE-2022-20277P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20277 [MEDIUM] CWE-203 CVE-2022-20277: In DevicePolicyManager, there is a possible way to determine whether an app is installed, without qu
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID
nvd
CVE-2022-20332P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20332 [MEDIUM] CVE-2022-20332: In PackageManager, there is a possible way to determine whether an app is installed, without query p
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-180019130
nvd
CVE-2022-20291P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20291 [MEDIUM] CWE-203 CVE-2022-20291: In AppOpsService, there is a possible way to determine whether an app is installed, without query pe
In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-20
nvd
CVE-2022-20275P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20275 [MEDIUM] CWE-203 CVE-2022-20275: In DevicePolicyManager, there is a possible way to determine whether an app is installed, without qu
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID
nvd
CVE-2022-20293P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20293 [MEDIUM] CWE-203 CVE-2022-20293: In LauncherApps, there is a possible way to determine whether an app is installed, without query per
In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202
nvd
CVE-2022-20279P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20279 [MEDIUM] CWE-203 CVE-2022-20279: In DevicePolicyManager, there is a possible way to determine whether an app is installed, without qu
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID
nvd
CVE-2022-20289P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20289 [MEDIUM] CVE-2022-20289: In PackageInstaller, there is a possible way to determine whether an app is installed, without query
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-2036839
nvd
CVE-2022-20287P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20287 [MEDIUM] CVE-2022-20287: In AppSearchManagerService, there is a possible way to determine whether an app is installed, withou
In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-
nvd
CVE-2022-20276P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20276 [MEDIUM] CWE-203 CVE-2022-20276: In DevicePolicyManager, there is a possible way to determine whether an app is installed, without qu
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID
nvd
CVE-2021-25460P4MEDIUMCVSS 5.5v10.0v11.02021-09-09
CVE-2021-25460 [MEDIUM] CWE-285 CVE-2021-25460: An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 R
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
nvd
CVE-2022-42756P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42756 [MEDIUM] CWE-120 CVE-2022-42756: In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead
In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.
nvd
CVE-2022-39131P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-39131 [MEDIUM] CWE-119 CVE-2022-39131: In camera driver, there is a possible memory corruption due to improper locking. This could lead to
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
nvd
CVE-2022-47342P4MEDIUMCVSS 5.5v10.0v11.02023-02-12
CVE-2022-47342 [MEDIUM] CWE-129 CVE-2022-47342: In engineermode services, there is a missing permission check. This could lead to local denial of se
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
nvd