cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 325 of 339
CVE-2022-27831P4MEDIUMCVSS 4.4v10.0v11.0+1 more2022-04-11
CVE-2022-27831 [MEDIUM] CWE-125 CVE-2022-27831: Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allo Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.
nvd
CVE-2022-48386P4MEDIUMCVSS 4.4v11.0v12.02023-05-09
CVE-2022-48386 [MEDIUM] CWE-416 CVE-2022-48386: the apipe driver, there is a possible use after free due to a logic error. This could lead to local the apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2022-48236P4MEDIUMCVSS 4.4v10.0v11.0+2 more2023-05-09
CVE-2022-48236 [MEDIUM] CWE-125 CVE-2022-48236: In MP3 encoder, there is a possible out of bounds read due to a missing bounds check. This could lea In MP3 encoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2024-20152P4MEDIUMCVSS 4.4v13.0v14.0+1 more2025-01-06
CVE-2024-20152 [MEDIUM] CWE-617 CVE-2024-20152: In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.
nvd
CVE-2022-48450P4MEDIUMCVSS 4.4v10.0v11.0+1 more2023-07-12
CVE-2022-48450 [MEDIUM] CVE-2022-48450: In bluetooth service, there is a possible missing params check. This could lead to local denial of In bluetooth service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2022-48452P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-09-04
CVE-2022-48452 [MEDIUM] CWE-862 CVE-2022-48452: In Ifaa service, there is a possible missing permission check. This could lead to local denial of se In Ifaa service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2023-20823P4MEDIUMCVSS 4.4v12.0v13.02023-09-04
CVE-2023-20823 [MEDIUM] CWE-125 CVE-2023-20823: In cmdq, there is a possible out of bounds read due to an incorrect status check. This could lead to In cmdq, there is a possible out of bounds read due to an incorrect status check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08021592; Issue ID: ALPS08021592.
nvd
CVE-2023-40638P4MEDIUMCVSS 4.4v11.02023-10-08
CVE-2023-40638 [MEDIUM] CWE-862 CVE-2023-40638: In Telecom service, there is a possible missing permission check. This could lead to local denial of In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2023-52536P4MEDIUMCVSS 4.4v12.0v13.0+1 more2024-04-08
CVE-2023-52536 [MEDIUM] CWE-125 CVE-2023-52536: In faceid service, there is a possible out of bounds read due to a missing bounds check. This could In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2024-39434P4MEDIUMCVSS 4.4v13.0v14.02024-09-27
CVE-2024-39434 [MEDIUM] CWE-125 CVE-2024-39434: In drm service, there is a possible out of bounds read due to a missing bounds check. This could lea In drm service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2022-20243P4MEDIUMCVSS 4.4v13.0.0vAndroid-132022-08-11
CVE-2022-20243 [MEDIUM] CWE-319 CVE-2022-20243: In Core Utilities, there is a possible log information disclosure. This could lead to local informat In Core Utilities, there is a possible log information disclosure. This could lead to local information disclosure of sensitive browsing data with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-190199986
nvd
CVE-2023-20847P4MEDIUMCVSS 4.2v11.0v12.02023-09-04
CVE-2023-20847 [MEDIUM] CWE-125 CVE-2023-20847: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108.
nvd
CVE-2022-32645P4MEDIUMCVSS 4.1v11.0v12.0+1 more2023-01-03
CVE-2022-32645 [MEDIUM] CWE-362 CVE-2022-32645: In vow, there is a possible information disclosure due to a race condition. This could lead to local In vow, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494477; Issue ID: ALPS07494477.
nvd
CVE-2025-20651P4MEDIUMCVSS 4.1v13.0v14.0+1 more2025-03-03
CVE-2025-20651 [MEDIUM] CWE-125 CVE-2025-20651: In da, there is a possible out of bounds read due to a missing bounds check. This could lead to loca In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2062.
nvd
CVE-2022-48451P4MEDIUMCVSS 4.1v10.0v11.0+2 more2023-07-12
CVE-2022-48451 [MEDIUM] CWE-362 CVE-2022-48451: In bluetooth service, there is a possible out of bounds write due to race condition. This could lea In bluetooth service, there is a possible out of bounds write due to race condition. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2016-0823P4MEDIUMCVSS 4.0v6.0.12016-03-12
CVE-2016-0823 [MEDIUM] CWE-200 CVE-2016-0823: The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Androi The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
nvd
CVE-2023-20838P4MEDIUMCVSS 4.0v12.0v13.02023-09-04
CVE-2023-20838 [MEDIUM] CWE-125 CVE-2023-20838: In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326418.
nvd
CVE-2022-20226P4LOWCVSS 3.9v12.0v12.1+1 more2022-07-13
CVE-2022-20226 [LOW] CWE-1021 CVE-2022-20226: In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213644870
nvd
CVE-2009-2999P4MEDIUMCVSS 4.3v1.52009-10-14
CVE-2009-2999 [MEDIUM] CVE-2009-2999: The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of serv The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsException exception, possibly a related issue to CVE-2009-2656.
nvd
CVE-2012-4222P4MEDIUMCVSS 4.3v2.3v2.3.1+20 more2012-11-30
CVE-2012-4222 [MEDIUM] CWE-20 CVE-2012-4222: drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2 allows attackers to cause a denial of service (NULL pointer dereference) via an application that uses crafted arguments in a local kgsl_ioctl call.
nvd
Google Android vulnerabilities | cvebase