Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 305 of 339
CVE-2023-21314P4MEDIUMCVSS 4.4fixed in 14.0v142023-10-30
CVE-2023-21314 [MEDIUM] CWE-125 CVE-2023-21314: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20798P4MEDIUMCVSS 4.4v12.0v13.02023-08-07
CVE-2023-20798 [MEDIUM] CWE-125 CVE-2023-20798: In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This
In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147572; Issue ID: ALPS07421076.
nvd
CVE-2024-29755P4MEDIUMCVSS 4.4vAndroid kernel2024-04-05
CVE-2024-29755 [MEDIUM] CWE-125 CVE-2024-29755: In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. Thi
In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20813P4MEDIUMCVSS 4.4v12.0v13.02023-08-07
CVE-2023-20813 [MEDIUM] CWE-125 CVE-2023-20813: In wlan service, there is a possible out of bounds read due to improper input validation. This could
In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453549; Issue ID: ALPS07453549.
nvd
CVE-2023-20818P4MEDIUMCVSS 4.4v12.0v13.02023-08-07
CVE-2023-20818 [MEDIUM] CWE-125 CVE-2023-20818: In wlan service, there is a possible out of bounds read due to improper input validation. This could
In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460540; Issue ID: ALPS07460540.
nvd
CVE-2023-52346P4MEDIUMCVSS 4.4v12.0v13.0+1 more2024-04-08
CVE-2023-52346 [MEDIUM] CWE-120 CVE-2023-52346: In modem driver, there is a possible system crash due to improper input validation. This could lead
In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed
nvd
CVE-2023-21357P4MEDIUMCVSS 4.4v14.0v142023-10-30
CVE-2023-21357 [MEDIUM] CWE-125 CVE-2023-21357: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35653P4MEDIUMCVSS 4.4vAndroid kernel2023-10-11
CVE-2023-35653 [MEDIUM] CWE-863 CVE-2023-35653: In TBD of TBD, there is a possible way to access location information due to a permissions bypass. T
In TBD of TBD, there is a possible way to access location information due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20790P4MEDIUMCVSS 4.4v12.0v13.02023-08-07
CVE-2023-20790 [MEDIUM] CWE-787 CVE-2023-20790: In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID: ALPS07740194.
nvd
CVE-2024-20036P4MEDIUMCVSS 4.4v12.0v13.0+1 more2024-03-04
CVE-2024-20036 [MEDIUM] CWE-284 CVE-2024-20036: In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local
In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.
nvd
CVE-2023-52535P4MEDIUMCVSS 4.4v12.0v13.02024-04-08
CVE-2023-52535 [MEDIUM] CWE-20 CVE-2023-52535: In vsp driver, there is a possible missing verification incorrect input. This could lead to local de
In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2025-20789P4MEDIUMCVSS 4.4v15.02025-12-02
CVE-2025-20789 [MEDIUM] CWE-201 CVE-2025-20789: In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could le
In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS10117741; Issue ID: MSV-4538.
nvd
CVE-2026-20424P4MEDIUMCVSS 4.4v15.0v16.02026-03-02
CVE-2026-20424 [MEDIUM] CWE-125 CVE-2026-20424: In display, there is a possible out of bounds read due to a missing bounds check. This could lead to
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5540.
nvd
CVE-2026-20429P4MEDIUMCVSS 4.4v14.0v15.0+1 more2026-03-02
CVE-2026-20429 [MEDIUM] CWE-125 CVE-2026-20429: In display, there is a possible out of bounds read due to a missing bounds check. This could lead to
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5535.
nvd
CVE-2022-42768P4MEDIUMCVSS 4.3v10.0v11.0+1 more2022-12-06
CVE-2022-42768 [MEDIUM] CWE-126 CVE-2022-42768: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2025-20638P4MEDIUMCVSS 4.3v12.0v13.0+2 more2025-02-03
CVE-2025-20638 [MEDIUM] CWE-457 CVE-2025-20638: In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lea
In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291449; Issue ID: MSV-2066.
nvd
CVE-2024-20026P4MEDIUMCVSS 4.2v12.0v13.0+1 more2024-03-04
CVE-2024-20026 [MEDIUM] CVE-2024-20026: In da, there is a possible information disclosure due to improper input validation. This could lead
In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541632.
nvd
CVE-2023-20620P4MEDIUMCVSS 4.1v12.0v13.02023-03-07
CVE-2023-20620 [MEDIUM] CWE-367 CVE-2023-20620: In adsp, there is a possible escalation of privilege due to a logic error. This could lead to local
In adsp, there is a possible escalation of privilege due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07554558; Issue ID: ALPS07554558.
nvd
CVE-2021-25391P4MEDIUMCVSS 4.0v11.02021-06-11
CVE-2021-25391 [MEDIUM] CWE-926 CVE-2021-25391: Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers t
Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
nvd
CVE-2021-25390P4MEDIUMCVSS 4.0v8.1v9.0+2 more2021-06-11
CVE-2021-25390 [MEDIUM] CWE-926 CVE-2021-25390: Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to e
Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
nvd