cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 333 of 339
CVE-2022-20336P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20336 [LOW] CWE-862 CVE-2022-20336: In Settings, there is a possible installed application disclosure due to a missing permission check. In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to local information disclosure of applications allow-listed to use the network during VPN lockdown mode with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13
nvd
CVE-2022-20262P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20262 [LOW] CWE-862 CVE-2022-20262: In ActivityManager, there is a possible way to check another process's capabilities due to a missing In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-218338453
nvd
CVE-2022-20315P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20315 [LOW] CWE-862 CVE-2022-20315: In ActivityManager, there is a possible disclosure of installed packages due to a missing permission In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-191058227
nvd
CVE-2022-20305P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20305 [LOW] CWE-862 CVE-2022-20305: In ContentService, there is a possible disclosure of available account types due to a missing permis In ContentService, there is a possible disclosure of available account types due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-199751623
nvd
CVE-2022-33718P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33718 [LOW] CWE-863 CVE-2022-33718: An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows unt An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
nvd
CVE-2022-33701P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33701 [LOW] CWE-284 CVE-2022-33701: Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 al Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
nvd
CVE-2023-21349P4LOWCVSS 3.3fixed in 14.0v142023-10-30
CVE-2023-21349 [LOW] CWE-203 CVE-2023-21349: In Package Manager, there is a possible way to determine whether an app is installed, without query In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21346P4LOWCVSS 3.3fixed in 14.0v142023-10-30
CVE-2023-21346 [LOW] CWE-203 CVE-2023-21346: In the Device Idle Controller, there is a possible way to determine whether an app is installed, wit In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21348P4LOWCVSS 3.3fixed in 14.0v142023-10-30
CVE-2023-21348 [LOW] CWE-203 CVE-2023-21348: In Window Manager, there is a possible way to determine whether an app is installed, without query p In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21345P4LOWCVSS 3.3fixed in 14.0v142023-10-30
CVE-2023-21345 [LOW] CWE-203 CVE-2023-21345: In Game Manager Service, there is a possible way to determine whether an app is installed, without q In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-39886P4LOWCVSS 3.3v10.0v11.0+1 more2022-11-09
CVE-2022-39886 [LOW] CWE-280 CVE-2022-39886: Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Re Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
nvd
CVE-2022-39885P4LOWCVSS 3.3v10.0v11.0+1 more2022-11-09
CVE-2022-39885 [LOW] CWE-280 CVE-2022-39885: Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
nvd
CVE-2022-39879P4LOWCVSS 3.3v11.0v12.02022-11-09
CVE-2022-39879 [LOW] CWE-285 CVE-2022-39879: Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
nvd
CVE-2015-6641P4LOWCVSS 3.1v6.02016-01-06
CVE-2015-6641 [LOW] CWE-200 CVE-2015-6641: Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts info Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.
nvd
CVE-2021-25335P4LOWCVSS 2.5v10.02021-03-04
CVE-2021-25335 [LOW] CWE-703 CVE-2021-25335: Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2 Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.
nvd
CVE-2016-3759P4LOWCVSS 3.3v5.0v5.0.1+4 more2016-07-11
CVE-2016-3759 [LOW] CWE-200 CVE-2016-3759: The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allo The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.
nvd
CVE-2022-27576P4LOWCVSS 3.3v10.0v11.0+1 more2022-04-11
CVE-2022-27576 [LOW] CWE-200 CVE-2022-27576: Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to a Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission
nvd
CVE-2022-27575P4LOWCVSS 3.3v10.0v11.0+1 more2022-04-11
CVE-2022-27575 [LOW] CWE-200 CVE-2022-27575: Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.
nvd
CVE-2022-22270P4LOWCVSS 3.3v9.0v10.0+1 more2022-01-10
CVE-2022-22270 [LOW] CWE-94 CVE-2022-22270: An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivil An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
nvd
CVE-2019-9277P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2019-9277 [LOW] CWE-532 CVE-2019-9277: In the proc filesystem, there is a possible information disclosure due to log information disclosure In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-68016944
nvd
Google Android vulnerabilities | cvebase