cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 299 of 339
CVE-2020-0141P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0141 [MEDIUM] CWE-362 CVE-2020-0141: In OutputBuffersArray::realloc of CCodecBuffers.cpp, there is a possible heap disclosure due to a ra In OutputBuffersArray::realloc of CCodecBuffers.cpp, there is a possible heap disclosure due to a race condition. This could lead to remote information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142544793
nvd
CVE-2015-3833P4MEDIUMCVSS 4.3≤ 5.12015-10-01
CVE-2015-3833 [MEDIUM] CWE-284 CVE-2015-3833: The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerServi The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground application via a crafted application, aka internal bug 20034603.
nvd
CVE-2023-20992P4MEDIUMCVSS 4.5v13.0vAndroid-132023-03-24
CVE-2023-20992 [MEDIUM] CWE-125 CVE-2023-20992: In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missi In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260568750
nvd
CVE-2023-20988P4MEDIUMCVSS 4.5v13.0vAndroid-132023-03-24
CVE-2023-20988 [MEDIUM] CWE-125 CVE-2023-20988: In btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bou In btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260569232
nvd
CVE-2023-21202P4MEDIUMCVSS 4.5v13.0vAndroid-132023-06-28
CVE-2023-21202 [MEDIUM] CWE-125 CVE-2023-21202: In btm_delete_stored_link_key_complete of btm_devctl.cc, there is a possible out of bounds read due In btm_delete_stored_link_key_complete of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over Bluetooth with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260568359
nvd
CVE-2024-20041P4MEDIUMCVSS 4.4v12.0v13.0+1 more2024-04-01
CVE-2024-20041 [MEDIUM] CWE-125 CVE-2024-20041: In da, there is a possible out of bounds read due to a missing bounds check. This could lead to loca In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541746; Issue ID: ALPS08541746.
nvd
CVE-2020-0060P4MEDIUMCVSS 4.4v10.0vAndroid-102020-03-10
CVE-2020-0060 [MEDIUM] CWE-89 CVE-2020-0060: In query of SmsProvider.java and MmsSmsProvider.java, there is a possible permission bypass due to S In query of SmsProvider.java and MmsSmsProvider.java, there is a possible permission bypass due to SQL injection. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143229845
nvd
CVE-2022-32639P4MEDIUMCVSS 4.4v11.0v12.02023-01-03
CVE-2022-32639 [MEDIUM] CWE-125 CVE-2022-32639: In watchdog, there is a possible out of bounds read due to a missing bounds check. This could lead t In watchdog, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494487; Issue ID: ALPS07494487.
nvd
CVE-2021-25468P4MEDIUMCVSS 4.4v10.0v11.02021-10-06
CVE-2021-25468 [MEDIUM] CWE-20 CVE-2021-25468: A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.
nvd
CVE-2018-9383P4MEDIUMCVSS 4.4vAndroid kernel2025-01-17
CVE-2018-9383 [MEDIUM] CWE-125 CVE-2018-9383: In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bound In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9384P4MEDIUMCVSS 4.4vAndroid Kernel2025-01-17
CVE-2018-9384 [MEDIUM] CWE-200 CVE-2018-9384: In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This co In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-25411P4MEDIUMCVSS 4.4v10.0v11.02021-06-11
CVE-2021-25411 [MEDIUM] CWE-94 CVE-2021-25411: Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root pri Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.
nvd
CVE-2023-42735P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-12-04
CVE-2023-42735 [MEDIUM] CWE-862 CVE-2023-42735: In telephony service, there is a possible missing permission check. This could lead to local informa In telephony service, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
nvd
CVE-2023-32808P4MEDIUMCVSS 4.4v13.02023-09-04
CVE-2023-32808 [MEDIUM] CVE-2023-32808: In bluetooth driver, there is a possible read and write access to registers due to improper access c In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07849751; Issue ID: ALPS07849751.
nvd
CVE-2023-32809P4MEDIUMCVSS 4.4v13.02023-09-04
CVE-2023-32809 [MEDIUM] CVE-2023-32809: In bluetooth driver, there is a possible read and write access to registers due to improper access c In bluetooth driver, there is a possible read and write access to registers due to improper access control of register interface. This could lead to local leak of sensitive information with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07849753; Issue ID: ALPS07849753.
nvd
CVE-2023-20956P4MEDIUMCVSS 4.4v12.0v12.1+2 more2023-03-24
CVE-2023-20956 [MEDIUM] CWE-787 CVE-2023-20956: In Import of C2SurfaceSyncObj.cpp, there is a possible out of bounds write due to a missing bounds c In Import of C2SurfaceSyncObj.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-240140929
nvd
CVE-2023-20679P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-04-06
CVE-2023-20679 [MEDIUM] CWE-125 CVE-2023-20679: In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to lo In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588413; Issue ID: ALPS07588453.
nvd
CVE-2023-32813P4MEDIUMCVSS 4.4v13.02023-09-04
CVE-2023-32813 [MEDIUM] CWE-787 CVE-2023-32813: In gnss service, there is a possible out of bounds write due to improper input validation. This coul In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017370; Issue ID: ALPS08017370.
nvd
CVE-2023-21379P4MEDIUMCVSS 4.4fixed in 14.0v142023-10-30
CVE-2023-21379 [MEDIUM] CWE-125 CVE-2023-21379: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21297P4MEDIUMCVSS 4.4fixed in 14.0v142023-10-30
CVE-2023-21297 [MEDIUM] CWE-287 CVE-2023-21297: In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase