cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 337 of 339
CVE-2022-20327P4LOWCVSS 2.8v13.0vAndroid-132022-08-12
CVE-2022-20327 [LOW] CWE-862 CVE-2022-20327: In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a mi In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-185126813
nvd
CVE-2022-20529P4LOWCVSS 2.4v13.0vAndroid-132022-12-16
CVE-2022-20529 [LOW] CWE-862 CVE-2022-20529: In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231583603
nvd
CVE-2022-20543P4LOWCVSS 2.3v13.0vAndroid-132022-12-16
CVE-2022-20543 [LOW] CWE-1284 CVE-2022-20543: In multiple locations, there is a possible display crash loop due to improper input validation. This In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238178261
nvd
CVE-2020-0382P4LOWCVSS 2.3v10.0v11.0+1 more2020-09-17
CVE-2020-0382 [LOW] CWE-755 CVE-2020-0382: In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exceptio In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-152944488
nvd
CVE-2024-20045P4LOWCVSS 2.3v12.0v13.0+1 more2024-04-01
CVE-2024-20045 [LOW] CWE-125 CVE-2024-20045: In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. Thi In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08024748; Issue ID: ALPS08029526.
nvd
CVE-2022-33720P4LOWCVSS 2.4v10.0v11.02022-08-05
CVE-2022-33720 [LOW] CWE-284 CVE-2022-33720: Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical att Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.
nvd
CVE-2019-20595P4LOWCVSS 2.4v9.02020-03-24
CVE-2019-20595 [LOW] CWE-306 CVE-2019-20595: An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Bluetooth stack without authentication. The Samsung ID is SVE-2019-14545 (July 2019).
nvd
CVE-2024-34664P4LOWCVSS 2.4v12.0v13.0+1 more2024-10-08
CVE-2024-34664 [LOW] CWE-754 CVE-2024-34664: Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physica Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.
nvd
CVE-2022-33693P4LOWCVSS 2.3v10.0v11.0+1 more2022-07-12
CVE-2022-33693 [LOW] CWE-200 CVE-2022-33693: Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attack Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
nvd
CVE-2024-20051P4LOWCVSS 2.3v12.0v13.0+1 more2024-04-01
CVE-2024-20051 [LOW] CVE-2024-20051: In flashc, there is a possible system crash due to an uncaught exception. This could lead to local d In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.
nvd
CVE-2016-3888P4LOWCVSS 2.1v4.0v4.0.1+21 more2016-09-11
CVE-2016-3888 [LOW] CWE-264 CVE-2016-3888: internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS messages during the Setup Wizard provisioning stage, via unspecified vectors, aka
nvd
CVE-2026-0115P4LOWCVSS 2.1vAndroid kernel2026-03-10
CVE-2026-0115 [LOW] CWE-1300 CVE-2026-0115: In Trusted Execution Environment, there is a possible key leak due to side channel information discl In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-0991P4LOWCVSS 2.4v12.0vAndroid-122021-12-15
CVE-2021-0991 [LOW] CWE-532 CVE-2021-0991: In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible l In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181
nvd
CVE-2022-36857P4LOWCVSS 2.4v11.02022-09-09
CVE-2022-36857 [LOW] CWE-285 CVE-2022-36857: Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
nvd
CVE-2018-21046P4LOWCVSS 2.4v8.0v8.12020-04-08
CVE-2018-21046 [LOW] CWE-862 CVE-2018-21046: An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Expo An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Exposure via the Emergency Dialer upon connecting a USB device. The Samsung ID is SVE-2018-12911 (November 2018).
nvd
CVE-2021-25513P4LOWCVSS 2.4v11.02021-12-08
CVE-2021-25513 [LOW] CWE-269 CVE-2021-25513: An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Releas An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.
nvd
CVE-2020-0029P4LOWCVSS 2.3v10.0vAndroid-102020-03-10
CVE-2020-0029 [LOW] CWE-200 CVE-2020-0029: In the WifiConfigManager, there is a possible storage of location history which can only be deleted In the WifiConfigManager, there is a possible storage of location history which can only be deleted by triggering a factory reset. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140065828
nvd
CVE-2022-33686P4LOWCVSS 2.3v10.0v11.0+1 more2022-07-12
CVE-2022-33686 [LOW] CWE-200 CVE-2022-33686: Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local at Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
nvd
CVE-2022-33700P4LOWCVSS 2.3v10.0v11.0+1 more2022-07-12
CVE-2022-33700 [LOW] CWE-200 CVE-2022-33700: Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 al Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
nvd
CVE-2022-33699P4LOWCVSS 2.3v10.0v11.0+1 more2022-07-12
CVE-2022-33699 [LOW] CWE-200 CVE-2022-33699: Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 al Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
nvd
Google Android vulnerabilities | cvebase