cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 336 of 339
CVE-2021-1031P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-1031 [LOW] CWE-203 CVE-2021-1031: In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to de In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod
nvd
CVE-2021-0989P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0989 [LOW] CWE-203 CVE-2021-0989: In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr
nvd
CVE-2021-0983P4LOWCVSS 3.3v12.1vAndroid-12L2021-12-15
CVE-2021-0983 [LOW] CWE-200 CVE-2021-0983: In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of in In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:
nvd
CVE-2021-0988P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0988 [LOW] CWE-203 CVE-2021-0988: In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possib In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo
nvd
CVE-2021-1032P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-1032 [LOW] CWE-203 CVE-2021-1032: In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app i In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An
nvd
CVE-2021-0990P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0990 [LOW] CWE-203 CVE-2021-0990: In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app i In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An
nvd
CVE-2021-0987P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0987 [LOW] CWE-203 CVE-2021-0987: In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whethe In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe
nvd
CVE-2021-1018P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-1018 [LOW] CWE-203 CVE-2021-1018: In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is i In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro
nvd
CVE-2021-1015P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-1015 [LOW] CWE-203 CVE-2021-1015: In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2021-0978P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0978 [LOW] CWE-862 CVE-2021-0978: In getSerialForPackage of DeviceIdentifiersPolicyService.java, there is a possible way to determine In getSerialForPackage of DeviceIdentifiersPolicyService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr
nvd
CVE-2022-22267P4LOWCVSS 3.3v9.0v10.0+2 more2022-01-10
CVE-2022-22267 [LOW] CWE-285 CVE-2022-22267: Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 all Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
nvd
CVE-2022-20320P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20320 [LOW] CWE-203 CVE-2022-20320: In ActivityManager, there is a possible way to determine whether an app is installed, without query In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-1879
nvd
CVE-2022-20318P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20318 [LOW] CWE-203 CVE-2022-20318: In PackageInstaller, there is a possible way to determine whether an app is installed, without query In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-19
nvd
CVE-2022-20307P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20307 [LOW] CWE-203 CVE-2022-20307: In AlarmManagerService, there is a possible way to determine whether an app is installed, without qu In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A
nvd
CVE-2022-20309P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20309 [LOW] CWE-203 CVE-2022-20309: In PackageInstaller, there is a possible way to determine whether an app is installed, without query In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-19
nvd
CVE-2022-20316P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20316 [LOW] CWE-203 CVE-2022-20316: In ContentResolver, there is a possible way to determine whether an app is installed, without query In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-1907
nvd
CVE-2022-20252P4LOWCVSS 3.3v13.0.0vAndroid-132022-08-11
CVE-2022-20252 [LOW] CWE-203 CVE-2022-20252: In PackageManager, there is a possible way to determine whether an app is installed, without query p In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-2245
nvd
CVE-2022-20251P4LOWCVSS 3.3v13.0.0vAndroid-132022-08-11
CVE-2022-20251 [LOW] CWE-203 CVE-2022-20251: In LocaleManager, there is a possible way to determine whether an app is installed, without query pe In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-22588
nvd
CVE-2022-20249P4LOWCVSS 3.3v13.0.0vAndroid-132022-08-11
CVE-2022-20249 [LOW] CWE-203 CVE-2022-20249: In LocaleManager, there is a possible way to determine whether an app is installed, without query pe In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-22690
nvd
CVE-2011-3975P4LOWCVSS 2.6v2.3.42011-10-03
CVE-2011-3975 [LOW] CWE-200 CVE-2011-3975: A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain a list of telephone numbers from a log, and other sensitive information, by leveraging the android.permiss
nvd
Google Android vulnerabilities | cvebase