Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 308 of 339
CVE-2020-27028P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27028 [MEDIUM] CWE-125 CVE-2020-27028: In filter_incoming_event of hci_layer.cc, there is a possible out of bounds read due to a missing bo
In filter_incoming_event of hci_layer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-141618611
nvd
CVE-2020-0152P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0152 [MEDIUM] CWE-125 CVE-2020-0152: In avb_vbmeta_image_verify of avb_vbmeta_image.c, there is a possible out of bounds read due to a mi
In avb_vbmeta_image_verify of avb_vbmeta_image.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145992159
nvd
CVE-2020-0144P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0144 [MEDIUM] CWE-125 CVE-2020-0144: In btm_proc_sp_req_evt of btm_sec.cc, there is a possible out of bounds read due to a missing bounds
In btm_proc_sp_req_evt of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142543497
nvd
CVE-2020-0149P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0149 [MEDIUM] CWE-125 CVE-2020-0149: In btu_hcif_mode_change_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing
In btu_hcif_mode_change_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142544089
nvd
CVE-2020-27021P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27021 [MEDIUM] CWE-125 CVE-2020-27021: In avrc_ctrl_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a mis
In avrc_ctrl_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168712245
nvd
CVE-2020-27033P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27033 [MEDIUM] CWE-125 CVE-2020-27033: In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing
In nfc_ncif_proc_get_routing of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153655153
nvd
CVE-2020-27031P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27031 [MEDIUM] CWE-125 CVE-2020-27031: In nfc_data_event of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds che
In nfc_data_event of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151313205
nvd
CVE-2020-0325P4MEDIUMCVSS 4.4v11.0vAndroid-112020-09-18
CVE-2020-0325 [MEDIUM] CWE-20 CVE-2020-0325: In NFC, there is a missing bounds check. This could lead to local information disclosure with System
In NFC, there is a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145079309
nvd
CVE-2020-0328P4MEDIUMCVSS 4.4v11.0vAndroid-112020-09-17
CVE-2020-0328 [MEDIUM] CWE-125 CVE-2020-0328: In the camera, there is a possible out of bounds read due to an integer overflow. This could lead to
In the camera, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150156131
nvd
CVE-2020-0158P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0158 [MEDIUM] CWE-125 CVE-2020-0158: In nfc_ncif_proc_t3t_polling_ntf of nfc_ncif.cc, there is a possible out of bounds read due to a mis
In nfc_ncif_proc_t3t_polling_ntf of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141547128
nvd
CVE-2020-0143P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0143 [MEDIUM] CWE-125 CVE-2020-0143: In nfa_dm_ndef_find_next_handler of nfa_dm_ndef.c, there is a possible out of bounds read due to a m
In nfa_dm_ndef_find_next_handler of nfa_dm_ndef.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of heap data via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-
nvd
CVE-2020-0148P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0148 [MEDIUM] CWE-125 CVE-2020-0148: In btu_hcif_pin_code_request_evt, btu_hcif_link_key_request_evt, and btu_hcif_link_key_notification_
In btu_hcif_pin_code_request_evt, btu_hcif_link_key_request_evt, and btu_hcif_link_key_notification_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploit
nvd
CVE-2020-0147P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0147 [MEDIUM] CWE-125 CVE-2020-0147: In btu_hcif_esco_connection_chg_evt of btu_hcif.cc, there is a possible out of bounds read due to a
In btu_hcif_esco_connection_chg_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142638392
nvd
CVE-2020-0145P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0145 [MEDIUM] CWE-125 CVE-2020-0145: In btm_simple_pair_complete of btm_sec.cc, there is a possible out of bounds read due to a missing b
In btm_simple_pair_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142544079
nvd
CVE-2020-0146P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0146 [MEDIUM] CWE-125 CVE-2020-0146: In btu_hcif_hardware_error_evt of btu_hcif.cc, there is a possible out of bounds read due to a missi
In btu_hcif_hardware_error_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142546561
nvd
CVE-2020-0154P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0154 [MEDIUM] CWE-125 CVE-2020-0154: In nci_proc_core_rsp of nci_hrcv.cc, there is a possible out of bounds read due to an incorrect boun
In nci_proc_core_rsp of nci_hrcv.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141550919
nvd
CVE-2020-0139P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0139 [MEDIUM] CWE-125 CVE-2020-0139: In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overfl
In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malformed NFC tag is provided by the firmware. System execution privileges are needed and user interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-14552047
nvd
CVE-2020-0151P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0151 [MEDIUM] CWE-125 CVE-2020-0151: In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a mis
In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-133164384
nvd
CVE-2021-0404P4MEDIUMCVSS 4.4v11.0vAndroid-112021-02-26
CVE-2021-0404 [MEDIUM] CWE-20 CVE-2021-0404: In mobile_log_d, there is a possible information disclosure due to improper input validation. This c
In mobile_log_d, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05457039.
nvd
CVE-2022-20098P4MEDIUMCVSS 4.4v11.0v12.02022-05-03
CVE-2022-20098 [MEDIUM] CWE-862 CVE-2022-20098: In aee daemon, there is a possible information disclosure due to a missing permission check. This co
In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06419017.
nvd