cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 291 of 339
CVE-2022-47348P4MEDIUMCVSS 5.5v10.0v11.02023-02-12
CVE-2022-47348 [MEDIUM] CWE-129 CVE-2022-47348: In engineermode services, there is a missing permission check. This could lead to local denial of se In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
nvd
CVE-2022-47345P4MEDIUMCVSS 5.5v10.0v11.02023-02-12
CVE-2022-47345 [MEDIUM] CWE-129 CVE-2022-47345: In engineermode services, there is a missing permission check. This could lead to local denial of se In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
nvd
CVE-2022-47343P4MEDIUMCVSS 5.5v10.0v11.02023-02-12
CVE-2022-47343 [MEDIUM] CWE-129 CVE-2022-47343: In engineermode services, there is a missing permission check. This could lead to local denial of se In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
nvd
CVE-2022-47346P4MEDIUMCVSS 5.5v10.0v11.02023-02-12
CVE-2022-47346 [MEDIUM] CWE-129 CVE-2022-47346: In engineermode services, there is a missing permission check. This could lead to local denial of se In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
nvd
CVE-2022-47347P4MEDIUMCVSS 5.5v10.0v11.02023-02-12
CVE-2022-47347 [MEDIUM] CWE-129 CVE-2022-47347: In engineermode services, there is a missing permission check. This could lead to local denial of se In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
nvd
CVE-2022-47344P4MEDIUMCVSS 5.5v10.0v11.02023-02-12
CVE-2022-47344 [MEDIUM] CWE-129 CVE-2022-47344: In engineermode services, there is a missing permission check. This could lead to local denial of se In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
nvd
CVE-2022-47363P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47363 [MEDIUM] CWE-125 CVE-2022-47363: In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lea In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services.
nvd
CVE-2022-20242P4MEDIUMCVSS 5.5v13.0.0vAndroid-132022-08-11
CVE-2022-20242 [MEDIUM] CWE-203 CVE-2022-20242: In Telephony, there is a possible way to determine whether an app is installed, without query permis In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231986
nvd
CVE-2022-47487P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-05-09
CVE-2022-47487 [MEDIUM] CWE-120 CVE-2022-47487: In thermal service, there is a possible out of bounds write due to a missing bounds check. This coul In thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local denial of service with no additional execution privileges.
nvd
CVE-2023-21260P4MEDIUMCVSS 5.5v10.0v11.0+3 more2023-07-13
CVE-2023-21260 [MEDIUM] CWE-346 CVE-2023-21260: In notification access permission dialog box, malicious application can embedded a very long service In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.
nvd
CVE-2022-42775P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42775 [MEDIUM] CWE-119 CVE-2022-42775: In camera driver, there is a possible memory corruption due to improper locking. This could lead to In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
nvd
CVE-2019-20775P4MEDIUMCVSS 5.5v9.02020-04-17
CVE-2019-20775 [MEDIUM] CWE-327 CVE-2019-20775: An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, a An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets) software. Weak encryption leads to local information disclosure. The LG ID is LVE-SMP-190010 (August 2019).
nvd
CVE-2016-6771P4MEDIUMCVSS 5.3v6.0v6.0.1+1 more2017-01-12
CVE-2016-6771 [MEDIUM] CWE-284 CVE-2016-6771: An elevation of privilege vulnerability in Telephony could enable a local malicious application to a An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-31566390.
nvd
CVE-2015-6605P4MEDIUMCVSS 5.0≤ 5.12015-10-06
CVE-2015-6605 [MEDIUM] CVE-2015-6605: mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process cr mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bugs 20915134 and 23142203, a different vulnerability than CVE-2015-7718.
nvd
CVE-2015-7718P4MEDIUMCVSS 5.0≤ 5.12015-10-06
CVE-2015-7718 [MEDIUM] CVE-2015-7718: mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.
nvd
CVE-2021-25477P4MEDIUMCVSS 4.9v9.0v10.0+1 more2021-10-06
CVE-2021-25477 [MEDIUM] CWE-415 CVE-2021-25477: An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows mod An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.
nvd
CVE-2022-20521P4MEDIUMCVSS 5.0v13.0vAndroid-132022-12-16
CVE-2022-20521 [MEDIUM] CWE-476 CVE-2022-20521: In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227203684
nvd
CVE-2019-2040P4MEDIUMCVSS 5.0v9.02019-04-19
CVE-2019-2040 [MEDIUM] CWE-125 CVE-2019-2040: In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122316913.
nvd
CVE-2020-0338P4MEDIUMCVSS 5.0v9.0v10.0+1 more2020-09-17
CVE-2020-0338 [MEDIUM] CVE-2020-0338: In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could l In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-123700107
nvd
CVE-2020-0092P4MEDIUMCVSS 5.0v10.0vAndroid-102020-05-14
CVE-2020-0092 [MEDIUM] CWE-200 CVE-2020-0092: In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensiti In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification content due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145135488
nvd
Google Android vulnerabilities | cvebase