cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 332 of 339
CVE-2021-0994P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0994 [LOW] CWE-862 CVE-2021-0994: In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine wheth In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2021-0982P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0982 [LOW] CWE-862 CVE-2021-0982: In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization n In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization name disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192368508
nvd
CVE-2022-36852P4LOWCVSS 3.3v11.0v12.02022-09-09
CVE-2022-36852 [LOW] CWE-285 CVE-2022-36852: Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local at Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.
nvd
CVE-2022-22266P4LOWCVSS 3.3v9.0v10.0+1 more2022-01-10
CVE-2022-22266 [LOW] CWE-269 CVE-2022-22266: (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity applicati (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
nvd
CVE-2022-22269P4LOWCVSS 3.3v9.0v10.0+1 more2022-01-10
CVE-2022-22269 [LOW] CWE-285 CVE-2022-22269: Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allo Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
nvd
CVE-2021-25472P4LOWCVSS 3.3v8.1v9.0+2 more2021-10-06
CVE-2021-25472 [LOW] CWE-264 CVE-2021-25472: An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
nvd
CVE-2022-33692P4LOWCVSS 3.3v11.0v12.02022-07-12
CVE-2022-33692 [LOW] CWE-213 CVE-2022-33692: Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows lo Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
nvd
CVE-2022-33687P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33687 [LOW] CWE-200 CVE-2022-33687: Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows loc Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
nvd
CVE-2022-33696P4LOWCVSS 3.3v12.02022-07-12
CVE-2022-33696 [LOW] CWE-213 CVE-2022-33696: Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
nvd
CVE-2021-25457P4LOWCVSS 3.3v10.0v11.02021-09-09
CVE-2021-25457 [LOW] CWE-20 CVE-2021-25457: An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows loca An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
nvd
CVE-2021-25486P4LOWCVSS 3.3v8.1v9.0+2 more2021-10-06
CVE-2021-25486 [LOW] CWE-200 CVE-2021-25486: Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.
nvd
CVE-2022-20340P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20340 [LOW] CWE-862 CVE-2022-20340: In SELinux policy, there is a possible way of inferring which websites are being opened in the brows In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-166269532
nvd
CVE-2022-20339P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20339 [LOW] CVE-2022-20339: In Android, there is a possible access of network neighbor table information due to an insecure SEpo In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. This could lead to local information disclosure of network topography with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-171572148
nvd
CVE-2022-20342P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20342 [LOW] CWE-1188 CVE-2022-20342: In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-143534321
nvd
CVE-2022-33729P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33729 [LOW] CWE-20 CVE-2022-33729: Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 R Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.
nvd
CVE-2022-33689P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33689 [LOW] CWE-287 CVE-2022-33689: Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attacker Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.
nvd
CVE-2021-25501P4LOWCVSS 3.3v10.0v11.02021-11-05
CVE-2021-25501 [LOW] CWE-284 CVE-2021-25501: An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR N An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
nvd
CVE-2022-20328P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20328 [LOW] CWE-862 CVE-2022-20328: In PackageManager, there is a possible way to determine whether an app is installed due to a missing In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-184948501
nvd
CVE-2022-33728P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33728 [LOW] CWE-200 CVE-2022-33728: Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attacker Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.
nvd
CVE-2022-20241P4LOWCVSS 3.3v13.0.0vAndroid-132022-08-11
CVE-2022-20241 [LOW] CWE-20 CVE-2022-20241: In Messaging, there is a possible way to attach a private file to an SMS message due to improper inp In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-217185011
nvd
Google Android vulnerabilities | cvebase