cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 326 of 339
CVE-2021-25473P4MEDIUMCVSS 4.4v11.02021-10-06
CVE-2021-25473 [MEDIUM] CWE-755 CVE-2021-25473: Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadi Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.
nvd
CVE-2021-25474P4MEDIUMCVSS 4.4v10.0v11.02021-10-06
CVE-2021-25474 [MEDIUM] CWE-755 CVE-2021-25474: Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspan Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.
nvd
CVE-2022-23429P4MEDIUMCVSS 4.4v10.0v11.0+1 more2022-02-11
CVE-2022-23429 [MEDIUM] CWE-125 CVE-2022-23429: An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.
nvd
CVE-2017-13268P4MEDIUMCVSS 4.3v5.1.1v6.0+6 more2018-04-04
CVE-2017-13268 [MEDIUM] CWE-200 CVE-2017-13268: A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67058064.
nvd
CVE-2017-13269P4MEDIUMCVSS 4.3v5.1.1v6.0+6 more2018-04-04
CVE-2017-13269 [MEDIUM] CWE-200 CVE-2017-13269: A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68818034.
nvd
CVE-2014-8610P4LOWCVSS 3.3≤ 4.4.4v1.0+41 more2014-12-15
CVE-2014-8610 [LOW] CWE-264 CVE-2014-8610: AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsRece AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which allows attackers to send stored SMS messages, and consequently transmit arbitrary new draft SMS messages or trigger additional per-message charges from a network operator for old messages, via a crafted application that broadcasts an i
nvd
CVE-2021-25455P4LOWCVSS 3.3v8.1v9.0+2 more2021-09-09
CVE-2021-25455 [LOW] CWE-125 CVE-2021-25455: OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attacke OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
nvd
CVE-2022-33690P4LOWCVSS 3.3v12.02022-07-12
CVE-2022-33690 [LOW] CWE-20 CVE-2022-33690: Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to acc Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.
nvd
CVE-2023-44124P4LOWCVSS 3.3v12.0v13.02023-09-27
CVE-2023-44124 [LOW] CWE-927 CVE-2023-44124: The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. T
nvd
CVE-2024-39440P4MEDIUMCVSS 4.4v13.0v14.02024-10-09
CVE-2024-39440 [MEDIUM] CWE-476 CVE-2024-39440: In DRM service, there is a possible system crash due to null pointer dereference. This could lead to In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.
nvd
CVE-2016-3764P4MEDIUMCVSS 4.0v4.0v4.0.1+20 more2016-07-11
CVE-2016-3764 [MEDIUM] CWE-20 CVE-2016-3764: media/libmediaplayerservice/MetadataRetrieverClient.cpp in mediaserver in Android 4.x before 4.4.4, media/libmediaplayerservice/MetadataRetrieverClient.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive pointer information via a crafted application, aka internal bug 28377502.
nvd
CVE-2016-3761P4MEDIUMCVSS 4.0v4.0v4.0.1+20 more2016-07-11
CVE-2016-3761 [MEDIUM] CWE-200 CVE-2016-3761: NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background application, aka internal bug 28300969.
nvd
CVE-2022-20338P4LOWCVSS 3.3v13.0vAndroid-11 Android-12 Android-12L2022-08-12
CVE-2022-20338 [LOW] CWE-20 CVE-2022-20338: In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to a local escalation of privilege, preventing processes from validating URIs correctly, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersion
nvd
CVE-2023-21246P4LOWCVSS 3.3v11.0v12.0+6 more2023-07-13
CVE-2023-21246 [LOW] CWE-754 CVE-2023-21246: In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification list In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20556P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20556 [LOW] CWE-862 CVE-2022-20556: In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the g In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13An
nvd
CVE-2022-20519P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20519 [LOW] CWE-862 CVE-2022-20519: In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure Wi In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224772678
nvd
CVE-2022-20525P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20525 [LOW] CWE-209 CVE-2022-20525: In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual v In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-22974276
nvd
CVE-2022-20558P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20558 [LOW] CWE-863 CVE-2022-20558: In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred T In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236264289
nvd
CVE-2022-20533P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20533 [LOW] CWE-862 CVE-2022-20533: In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-232798363
nvd
CVE-2022-20536P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20536 [LOW] CWE-862 CVE-2022-20536: In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mod In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235100180
nvd
Google Android vulnerabilities | cvebase