cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 318 of 339
CVE-2018-21080P4MEDIUMCVSS 4.6v7.0v7.1.0+2 more2020-04-08
CVE-2018-21080 [MEDIUM] CWE-326 CVE-2018-21080: An issue was discovered on Samsung mobile devices with N(7.x) software. A physically proximate attac An issue was discovered on Samsung mobile devices with N(7.x) software. A physically proximate attacker wielding a magnet can activate NFC to bypass the lockscreen. The Samsung ID is SVE-2017-10897 (March 2018).
nvd
CVE-2010-4832P4MEDIUMCVSS 4.3≤ 2.1v1.0+5 more2014-05-14
CVE-2010-4832 [MEDIUM] CWE-310 CVE-2010-4832: Android OS before 2.2 does not display the correct SSL certificate in certain cases, which might all Android OS before 2.2 does not display the correct SSL certificate in certain cases, which might allow remote attackers to spoof trusted web sites via a web page containing references to external sources in which (1) the certificate of the last loaded resource is checked, instead of for the main page, or (2) later certificates are not checked when the
nvd
CVE-2020-0017P4MEDIUMCVSS 4.4v8.0v8.1+3 more2020-02-13
CVE-2020-0017 [MEDIUM] CVE-2020-0017: In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiabl In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-123232892
nvd
CVE-2020-0291P4MEDIUMCVSS 4.4v11.0vAndroid-112020-09-18
CVE-2020-0291 [MEDIUM] CWE-125 CVE-2020-0291: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146032016
nvd
CVE-2020-0018P4MEDIUMCVSS 4.4v8.0v8.1+3 more2020-02-13
CVE-2020-0018 [MEDIUM] CWE-532 CVE-2020-0018: In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclo In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lead to local disclosure of user input with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139945049
nvd
CVE-2020-0292P4MEDIUMCVSS 4.4v11.0vAndroid-112020-09-18
CVE-2020-0292 [MEDIUM] CWE-125 CVE-2020-0292: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-110107252
nvd
CVE-2019-9253P4MEDIUMCVSS 4.4v10.0vAndroid-102019-09-27
CVE-2019-9253 [MEDIUM] CWE-922 CVE-2019-9253: In KeyStore, there is a possible storage of symmetric keys in the TEE instead of the strongbox due t In KeyStore, there is a possible storage of symmetric keys in the TEE instead of the strongbox due to a missing strongbox flag. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109769728
nvd
CVE-2019-9360P4MEDIUMCVSS 4.4v10.0vAndroid-102019-09-27
CVE-2019-9360 [MEDIUM] CWE-125 CVE-2019-9360: In the TEE, there's a possible out of bounds read due to a missing bounds check. This could lead to In the TEE, there's a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120610663
nvd
CVE-2022-20449P4MEDIUMCVSS 4.4v10.0v11.0+3 more2022-12-13
CVE-2022-20449 [MEDIUM] CWE-22 CVE-2022-20449: In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of syst In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-1
nvd
CVE-2020-0135P4MEDIUMCVSS 4.4v10.0vAndroid-102020-06-11
CVE-2020-0135 [MEDIUM] CWE-862 CVE-2020-0135: In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a mi In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150949837
nvd
CVE-2022-32595P4MEDIUMCVSS 4.4v10.0v11.0+1 more2023-02-06
CVE-2022-32595 [MEDIUM] CWE-125 CVE-2022-32595: In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lea In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446236; Issue ID: ALPS07446236.
nvd
CVE-2020-27043P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27043 [MEDIUM] CWE-125 CVE-2020-27043: In nfc_enabled of nfc_main.cc, there is a possible out of bounds read due to an incorrect increment. In nfc_enabled of nfc_main.cc, there is a possible out of bounds read due to an incorrect increment. This could lead to local information disclosure via firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155234594
nvd
CVE-2023-42724P4MEDIUMCVSS 4.4v11.02023-12-04
CVE-2023-42724 [MEDIUM] CWE-125 CVE-2023-42724: In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2022-20103P4MEDIUMCVSS 4.4v11.0v12.02022-05-03
CVE-2022-20103 [MEDIUM] CWE-59 CVE-2022-20103: In aee daemon, there is a possible information disclosure due to symbolic link following. This could In aee daemon, there is a possible information disclosure due to symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06282684.
nvd
CVE-2021-0403P4MEDIUMCVSS 4.4v11.0vAndroid-112021-02-26
CVE-2021-0403 [MEDIUM] CWE-862 CVE-2021-0403: In netdiag, there is a possible information disclosure due to a missing permission check. This could In netdiag, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05475124.
nvd
CVE-2022-26456P4MEDIUMCVSS 4.4v11.02022-09-06
CVE-2022-26456 [MEDIUM] CWE-59 CVE-2022-26456: In vow, there is a possible information disclosure due to a symbolic link following. This could lead In vow, there is a possible information disclosure due to a symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545473; Issue ID: ALPS06545473.
nvd
CVE-2022-20066P4MEDIUMCVSS 4.4v11.0v12.02022-04-11
CVE-2022-20066 [MEDIUM] CWE-755 CVE-2022-20066: In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. T In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171729; Issue ID: ALPS06171729.
nvd
CVE-2022-20015P4MEDIUMCVSS 4.4v10.0v11.02022-01-04
CVE-2022-20015 [MEDIUM] CWE-908 CVE-2022-20015: In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This c In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862966; Issue ID: ALPS05862966.
nvd
CVE-2022-20018P4MEDIUMCVSS 4.4v10.0v11.0+1 more2022-01-04
CVE-2022-20018 [MEDIUM] CWE-908 CVE-2022-20018: In seninf driver, there is a possible information disclosure due to uninitialized data. This could l In seninf driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05863018; Issue ID: ALPS05863018.
nvd
CVE-2021-0900P4MEDIUMCVSS 4.4v10.0v11.0+1 more2021-12-17
CVE-2021-0900 [MEDIUM] CWE-125 CVE-2021-0900: In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672055.
nvd
Google Android vulnerabilities | cvebase