cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 331 of 339
CVE-2019-9364P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2019-9364 [LOW] CWE-863 CVE-2019-9364: In AudioService, there is a possible trigger of background user audio due to a permissions bypass. T In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to local information disclosure by playing the background user's audio with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73364631
nvd
CVE-2022-39904P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-08
CVE-2022-39904 [LOW] CWE-200 CVE-2022-39904: Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.
nvd
CVE-2022-39906P4LOWCVSS 3.3v10.0v11.0+2 more2022-12-08
CVE-2022-39906 [LOW] CWE-284 CVE-2022-39906: Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.
nvd
CVE-2019-9292P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2019-9292 [LOW] CVE-2019-9292: In the Activity Manager service, there is a possible information disclosure due to a confused deputy In the Activity Manager service, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of current foreground process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115384617
nvd
CVE-2019-9351P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2019-9351 [LOW] CWE-862 CVE-2019-9351: In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Androi
nvd
CVE-2020-27056P4LOWCVSS 3.3v11.0vAndroid-112020-12-15
CVE-2020-27056 [LOW] CWE-862 CVE-2020-27056: In SELinux policies of mls, there is a missing permission check. This could lead to local informatio In SELinux policies of mls, there is a missing permission check. This could lead to local information disclosure of package metadata with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-161356067
nvd
CVE-2019-9377P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2019-9377 [LOW] CWE-862 CVE-2019-9377: In FingerprintService, there is a possible bypass for operating system protections that isolate user In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biometrics of another user on the device with no additional execution privileges needed. User interaction is not needed for
nvd
CVE-2018-6254P4LOWCVSS 3.3≤ 8.12018-05-10
CVE-2018-6254 [LOW] CWE-125 CVE-2018-6254: In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-64340684. Reference: N-CVE-2018-6254.
nvd
CVE-2020-27057P4LOWCVSS 3.3v11.0vAndroid-112020-12-15
CVE-2020-27057 [LOW] CWE-862 CVE-2020-27057: In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission by In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of gpu statistics with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-161903239
nvd
CVE-2021-25364P4LOWCVSS 3.3v11.02021-04-09
CVE-2021-25364 [LOW] CWE-200 CVE-2021-25364: A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unpr A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.
nvd
CVE-2022-36868P4LOWCVSS 3.3v11.0v12.02022-10-07
CVE-2022-36868 [LOW] CWE-20 CVE-2022-36868: Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 le Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.
nvd
CVE-2021-39628P4LOWCVSS 3.3v10.0v11.0+1 more2022-01-14
CVE-2021-39628 [LOW] CWE-668 CVE-2021-39628: In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-189575031
nvd
CVE-2022-39848P4LOWCVSS 3.3v10.0v11.0+1 more2022-10-07
CVE-2022-39848 [LOW] CWE-213 CVE-2022-39848: Exposure of sensitive information in AT_Distributor prior to SMR Oct-2022 Release 1 allows local att Exposure of sensitive information in AT_Distributor prior to SMR Oct-2022 Release 1 allows local attacker to access SerialNo via log.
nvd
CVE-2022-23999P4LOWCVSS 3.3v10.0v11.0+1 more2022-02-11
CVE-2022-23999 [LOW] CWE-20 CVE-2022-23999: PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local at PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
nvd
CVE-2022-24000P4LOWCVSS 3.3v10.0v11.0+1 more2022-02-11
CVE-2022-24000 [LOW] CWE-20 CVE-2022-24000: PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 a PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
nvd
CVE-2022-39895P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-08
CVE-2022-39895 [LOW] CWE-284 CVE-2022-39895: Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 a Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.
nvd
CVE-2022-39914P4LOWCVSS 3.3fixed in 13.02022-12-08
CVE-2022-39914 [LOW] CWE-200 CVE-2022-39914: Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManager Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.
nvd
CVE-2022-39903P4LOWCVSS 3.3v10.0v11.0+2 more2022-12-08
CVE-2022-39903 [LOW] CWE-200 CVE-2022-39903: Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attac Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.
nvd
CVE-2022-39912P4LOWCVSS 3.3fixed in 13.02022-12-08
CVE-2022-39912 [LOW] CWE-280 CVE-2022-39912: Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManag Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
nvd
CVE-2021-1034P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-1034 [LOW] CWE-862 CVE-2021-1034: In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine wheth In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is installed, without querypermissions due to a missing permission check. This could lead to localinformation disclosure with no additional execution privileges needed. Userinteraction is not needed for exploitation.Product: AndroidVersions: Andr
nvd
Google Android vulnerabilities | cvebase