Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 334 of 339
CVE-2018-9581P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2018-9581 [LOW] CWE-200 CVE-2018-9581: In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE an
In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.STATE_CHANGE intents. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111698366
nvd
CVE-2019-9440P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2019-9440 [LOW] CVE-2019-9440: In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead
In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of the Email app's protected files with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-37637796
nvd
CVE-2019-9438P4LOWCVSS 3.3v10.0vAndroid-102019-09-27
CVE-2019-9438 [LOW] CVE-2019-9438: In the Package Manager service, there is a possible information disclosure due to a confused deputy.
In the Package Manager service, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of information about installed packages for other users with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-77821568
nvd
CVE-2018-21043P4LOWCVSS 3.3v8.0v8.1+1 more2020-04-08
CVE-2018-21043 [LOW] CWE-200 CVE-2018-21043: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) soft
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is information disclosure about a kernel pointer in the g2d_drv driver because of logging. The Samsung ID is SVE-2018-13035 (December 2018).
nvd
CVE-2019-20625P4LOWCVSS 3.3v7.1v8.0+1 more2020-03-24
CVE-2019-20625 [LOW] CWE-532 CVE-2019-20625: An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software.
An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).
nvd
CVE-2019-20533P4LOWCVSS 3.3v7.0v7.1.0+5 more2020-03-24
CVE-2019-20533 [LOW] CWE-287 CVE-2019-20533: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is SVE-2019-13996 (December 2019).
nvd
CVE-2022-39856P4LOWCVSS 3.3v12.02022-10-07
CVE-2022-39856 [LOW] CWE-200 CVE-2022-39856: Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allo
Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information.
nvd
CVE-2022-39851P4LOWCVSS 3.3v10.0v11.0+1 more2022-10-07
CVE-2022-39851 [LOW] CWE-284 CVE-2022-39851: Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows l
Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.
nvd
CVE-2021-39739P4LOWCVSS 3.3v12.1vAndroid-12L2022-03-30
CVE-2021-39739 [LOW] CWE-532 CVE-2021-39739: In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosu
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-184525194
nvd
CVE-2021-25359P4LOWCVSS 3.3v10.0v11.02021-04-09
CVE-2021-25359 [LOW] CWE-284 CVE-2021-25359: An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP infor
An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.
nvd
CVE-2021-25358P4LOWCVSS 3.3v9.0v10.02021-04-09
CVE-2021-25358 [LOW] CWE-256 CVE-2021-25358: A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows l
A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.
nvd
CVE-2022-20321P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20321 [LOW] CWE-862 CVE-2022-20321: In Settings, there is a possible way for an application without permissions to read content of WiFi
In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187176859
nvd
CVE-2022-30728P4LOWCVSS 3.3v11.0v12.02022-06-07
CVE-2022-30728 [LOW] CWE-213 CVE-2022-30728: Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attacker
Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
nvd
CVE-2022-30714P4LOWCVSS 3.3v10.0v11.0+1 more2022-06-07
CVE-2022-30714 [LOW] CWE-213 CVE-2022-30714: Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local att
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
nvd
CVE-2022-33688P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33688 [LOW] CWE-532 CVE-2022-33688: Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
nvd
CVE-2022-33698P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33698 [LOW] CWE-200 CVE-2022-33698: Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows loca
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.
nvd
CVE-2022-33694P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33694 [LOW] CWE-213 CVE-2022-33694: Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local at
Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.
nvd
CVE-2022-33697P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33697 [LOW] CWE-532 CVE-2022-33697: Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-202
Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
nvd
CVE-2022-27832P4LOWCVSS 3.3v10.0v11.0+1 more2022-04-11
CVE-2022-27832 [LOW] CWE-125 CVE-2022-27832: Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers
Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.
nvd
CVE-2022-30753P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-30753 [LOW] CWE-200 CVE-2022-30753: Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 al
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
nvd