cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 335 of 339
CVE-2021-25519P4LOWCVSS 3.3v9.0v10.0+1 more2021-12-08
CVE-2021-25519 [LOW] CWE-200 CVE-2021-25519: An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attack An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.
nvd
CVE-2022-20311P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20311 [LOW] CWE-862 CVE-2022-20311: In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missi In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-192663553
nvd
CVE-2022-20310P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20310 [LOW] CWE-862 CVE-2022-20310: In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missi In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-192663798
nvd
CVE-2022-28794P4LOWCVSS 3.3v10.0v11.0+1 more2022-06-07
CVE-2022-28794 [LOW] CWE-213 CVE-2022-28794: Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows l Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.
nvd
CVE-2022-42757P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-06
CVE-2022-42757 [LOW] CWE-126 CVE-2022-42757: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2022-42758P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-06
CVE-2022-42758 [LOW] CWE-126 CVE-2022-42758: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2022-42769P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-06
CVE-2022-42769 [LOW] CWE-125 CVE-2022-42769: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2022-39884P4LOWCVSS 3.3v10.0v11.0+1 more2022-11-09
CVE-2022-39884 [LOW] CWE-284 CVE-2022-39884: Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local at Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.
nvd
CVE-2022-42767P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-06
CVE-2022-42767 [LOW] CWE-190 CVE-2022-42767: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
nvd
CVE-2022-33724P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33724 [LOW] CWE-200 CVE-2022-33724: Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allo Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.
nvd
CVE-2015-6627P4LOWCVSS 2.6≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6627 [LOW] CWE-200 CVE-2015-6627: The Audio component in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers The Audio component in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information via a crafted audio file, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24211743.
nvd
CVE-2021-25340P4LOWCVSS 2.4v10.02021-03-04
CVE-2021-25340 [LOW] CWE-284 CVE-2021-25340: Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 al Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
nvd
CVE-2021-25409P4LOWCVSS 2.4v10.02021-06-11
CVE-2021-25409 [LOW] CWE-703 CVE-2021-25409: Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.
nvd
CVE-2022-20240P4LOWCVSS 2.3v12.0vAndroid-12 Android-12L2022-12-13
CVE-2022-20240 [LOW] CWE-862 CVE-2022-20240: In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location infor In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-231496105
nvd
CVE-2017-0709P4LOWCVSS 3.3v7.1.22017-07-06
CVE-2017-0709 [LOW] CWE-200 CVE-2017-0709: A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: And A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.
nvd
CVE-2019-20623P4LOWCVSS 3.3v7.0v7.1.0+5 more2020-03-24
CVE-2019-20623 [LOW] CWE-908 CVE-2019-20623: An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery has uninitialized memory disclosure. The Samsung ID is SVE-2018-13060 (February 2019).
nvd
CVE-2018-21074P4LOWCVSS 3.3v6.0v6.0.12020-04-08
CVE-2018-21074 [LOW] CWE-200 CVE-2018-21074: An issue was discovered on Samsung mobile devices with M(6.x) (Exynos or Qualcomm chipsets) software An issue was discovered on Samsung mobile devices with M(6.x) (Exynos or Qualcomm chipsets) software. There is information disclosure from a Trustlet via the debug log. The Samsung ID is SVE-2017-10638 (April 2018).
nvd
CVE-2022-20535P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20535 [LOW] CWE-203 CVE-2022-20535: In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An
nvd
CVE-2022-20559P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20559 [LOW] CWE-203 CVE-2022-20559: In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whethe In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android
nvd
CVE-2021-0995P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0995 [LOW] CWE-203 CVE-2021-0995: In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to de In registerSuggestionConnectionStatusListener of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod
nvd
Google Android vulnerabilities | cvebase