Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 324 of 339
CVE-2018-21056P4MEDIUMCVSS 4.6v8.0v8.12020-04-08
CVE-2018-21056 [MEDIUM] CWE-200 CVE-2018-21056: An issue was discovered on Samsung mobile devices with O(8.x) software. The Smartwatch displays Secu
An issue was discovered on Samsung mobile devices with O(8.x) software. The Smartwatch displays Secure Folder Notification content. The Samsung ID is SVE-2018-12458 (September 2018).
nvd
CVE-2016-11048P4MEDIUMCVSS 4.6v5.0v5.12020-04-07
CVE-2016-11048 [MEDIUM] CWE-20 CVE-2016-11048: An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) s
An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-5421 (March 2016).
nvd
CVE-2019-20557P4MEDIUMCVSS 4.6v7.0v7.1.0+5 more2020-03-24
CVE-2019-20557 [MEDIUM] CVE-2019-20557: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Attacker
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card by blocking the PUK code. The Samsung ID is SVE-2019-15262 (October 2019).
nvd
CVE-2021-0350P4MEDIUMCVSS 4.4v8.1v9.0+3 more2021-02-04
CVE-2021-0350 [MEDIUM] CWE-20 CVE-2021-0350: In ged, there is a possible system crash due to an improper input validation. This could lead to loc
In ged, there is a possible system crash due to an improper input validation. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11; Patch ID: ALPS05342338.
nvd
CVE-2020-0476P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-0476 [MEDIUM] CWE-532 CVE-2020-0476: In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to log
In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162014574
nvd
CVE-2021-0352P4MEDIUMCVSS 4.4v10.0v11.0+1 more2021-02-03
CVE-2021-0352 [MEDIUM] CWE-843 CVE-2021-0352: In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to
In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05453809.
nvd
CVE-2020-0272P4MEDIUMCVSS 4.4v11.0vAndroid-112020-09-18
CVE-2020-0272 [MEDIUM] CWE-908 CVE-2020-0272: In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lea
In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-130166487
nvd
CVE-2022-48382P4MEDIUMCVSS 4.4v10.0v11.0+2 more2023-05-09
CVE-2022-48382 [MEDIUM] CWE-787 CVE-2022-48382: In log service, there is a possible out of bounds write due to a missing bounds check. This could le
In log service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2021-0549P4MEDIUMCVSS 4.4v11.0vAndroid-112021-06-22
CVE-2021-0549 [MEDIUM] CWE-532 CVE-2021-0549: In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses
In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183961896
nvd
CVE-2022-20107P4MEDIUMCVSS 4.4v9.0v10.0+1 more2022-05-03
CVE-2022-20107 [MEDIUM] CWE-190 CVE-2022-20107: In subtitle service, there is a possible application crash due to an integer overflow. This could le
In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID: DTV03330673.
nvd
CVE-2022-39089P4MEDIUMCVSS 4.4v10.0v11.02023-05-09
CVE-2022-39089 [MEDIUM] CWE-125 CVE-2022-39089: In mlog service, there is a possible out of bounds read due to a missing bounds check. This could le
In mlog service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2023-33903P4MEDIUMCVSS 4.4v10.0v11.0+2 more2023-07-12
CVE-2023-33903 [MEDIUM] CVE-2023-33903: In FM service, there is a possible missing params check. This could lead to local denial of service
In FM service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2023-33904P4MEDIUMCVSS 4.4v10.0v11.0+1 more2023-07-12
CVE-2023-33904 [MEDIUM] CWE-125 CVE-2023-33904: In hci_server, there is a possible out of bounds read due to a missing bounds check. This could lea
In hci_server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2021-0958P4MEDIUMCVSS 4.4v11.0v12.0+1 more2021-12-15
CVE-2021-0958 [MEDIUM] CVE-2021-0958: In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic er
In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-200041882
nvd
CVE-2021-1008P4MEDIUMCVSS 4.4v12.0vAndroid-122021-12-15
CVE-2021-1008 [MEDIUM] CVE-2021-1008: In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a fa
In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197327688
nvd
CVE-2021-25491P4MEDIUMCVSS 4.4v9.0v10.0+1 more2021-10-06
CVE-2021-25491 [MEDIUM] CWE-476 CVE-2021-25491: A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-poin
A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.
nvd
CVE-2023-42731P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-12-04
CVE-2023-42731 [MEDIUM] CWE-125 CVE-2023-42731: In Gnss service, there is a possible out of bounds read due to a missing bounds check. This could le
In Gnss service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2022-47486P4MEDIUMCVSS 4.4v10.0v11.02023-05-09
CVE-2022-47486 [MEDIUM] CWE-787 CVE-2022-47486: In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This c
In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2022-47470P4MEDIUMCVSS 4.4v10.0v11.02023-05-09
CVE-2022-47470 [MEDIUM] CWE-787 CVE-2022-47470: In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This c
In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with System execution privileges needed.
nvd
CVE-2022-47469P4MEDIUMCVSS 4.4v10.0v11.02023-05-09
CVE-2022-47469 [MEDIUM] CWE-787 CVE-2022-47469: In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This c
In ext4fsfilter driver, there is a possible out of bounds read due to a missing bounds check. This could local denial of service with System execution privileges needed.
nvd