cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 307 of 339
CVE-2018-21062P4MEDIUMCVSS 4.6v7.0v7.1.0+4 more2020-04-08
CVE-2018-21062 [MEDIUM] CWE-287 CVE-2018-21062: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. When biometric au An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. When biometric authentication is disabled, an attacker can view Streams content (e.g., a Gallery slideshow) of a locked Secure Folder via a connection to an external device. The Samsung ID is SVE-2018-11766 (August 2018).
nvd
CVE-2022-24932P4MEDIUMCVSS 4.6v10.0v11.0+1 more2022-03-10
CVE-2022-24932 [MEDIUM] CWE-424 CVE-2022-24932: Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Re Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.
nvd
CVE-2022-30729P4MEDIUMCVSS 4.6v12.02022-06-07
CVE-2022-30729 [MEDIUM] CWE-923 CVE-2022-30729: Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.
nvd
CVE-2022-25831P4MEDIUMCVSS 4.6v10.0v11.0+1 more2022-04-11
CVE-2022-25831 [MEDIUM] CWE-284 CVE-2022-25831: Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical at Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.
nvd
CVE-2024-39432P4MEDIUMCVSS 4.5v12.0v13.0+1 more2024-09-27
CVE-2024-39432 [MEDIUM] CWE-787 CVE-2024-39432: In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.
nvd
CVE-2011-4276P4MEDIUMCVSS 4.3v2.3v2.3.3+2 more2012-01-25
CVE-2011-4276 [MEDIUM] CWE-200 CVE-2011-4276: The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 a The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.
nvd
CVE-2015-1541P4MEDIUMCVSS 4.3≤ 5.12015-10-01
CVE-2015-1541 [MEDIUM] CWE-284 CVE-2015-1541: The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypass
nvd
CVE-2021-0605P4MEDIUMCVSS 4.4v11.0vAndroid kernel2021-06-22
CVE-2021-0605 [MEDIUM] CWE-125 CVE-2021-0605: In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. Thi In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-110373476
nvd
CVE-2020-0164P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0164 [MEDIUM] CWE-125 CVE-2020-0164: In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds read In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736125
nvd
CVE-2015-6624P4MEDIUMCVSS 4.3v6.02015-12-08
CVE-2015-6624 [MEDIUM] CWE-200 CVE-2015-6624: System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information via System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23999740.
nvd
CVE-2015-6625P4MEDIUMCVSS 4.3v6.02015-12-08
CVE-2015-6625 [MEDIUM] CWE-200 CVE-2015-6625: System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information and System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information and consequently gain privileges via a crafted application, aka internal bug 23936840.
nvd
CVE-2020-27023P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27023 [MEDIUM] CVE-2020-27023: In setErrorPlaybackState of BluetoothMediaBrowserService.java, there is a possible permission bypass In setErrorPlaybackState of BluetoothMediaBrowserService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156009462
nvd
CVE-2022-20555P4MEDIUMCVSS 4.4v13.0vAndroid-132022-12-16
CVE-2022-20555 [MEDIUM] CWE-125 CVE-2022-20555: In ufdt_get_node_by_path_len of ufdt_convert.c, there is a possible out of bounds read due to a miss In ufdt_get_node_by_path_len of ufdt_convert.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246194233
nvd
CVE-2020-0482P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-0482 [MEDIUM] CWE-125 CVE-2020-0482: In command of IncidentService.cpp, there is a possible out of bounds read due to an incorrect bounds In command of IncidentService.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150706572
nvd
CVE-2020-0058P4MEDIUMCVSS 4.4v10.0vAndroid-102020-03-10
CVE-2020-0058 [MEDIUM] CWE-125 CVE-2020-0058: In l2c_rcv_acl_data of l2c_main.cc, there is a possible out of bounds read due to an incorrect bound In l2c_rcv_acl_data of l2c_main.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141745011
nvd
CVE-2020-27046P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27046 [MEDIUM] CWE-125 CVE-2020-27046: In nfc_ncif_proc_ee_action of nfc_ncif.cc, there is a possible out of bounds read due to a missing b In nfc_ncif_proc_ee_action of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157649306
nvd
CVE-2021-0347P4MEDIUMCVSS 4.4v8.1v9.0+3 more2021-02-04
CVE-2021-0347 [MEDIUM] CWE-125 CVE-2021-0347: In ccu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc In ccu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11; Patch ID: ALPS05377188.
nvd
CVE-2023-21012P4MEDIUMCVSS 4.4v13.0vAndroid-132023-03-24
CVE-2023-21012 [MEDIUM] CWE-125 CVE-2023-21012: In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing boun In multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-257029812
nvd
CVE-2020-0349P4MEDIUMCVSS 4.4v11.0vAndroid-112020-09-18
CVE-2020-0349 [MEDIUM] CWE-125 CVE-2020-0349: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to loc In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139188779
nvd
CVE-2020-0322P4MEDIUMCVSS 4.4v11.0vAndroid-112020-09-17
CVE-2020-0322 [MEDIUM] CWE-125 CVE-2020-0322: In apexd, there is a possible out of bounds read due to a missing bounds check. This could lead to l In apexd, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147002540
nvd
Google Android vulnerabilities | cvebase