cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 43 of 339
CVE-2024-0023P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-16
CVE-2024-0023 [HIGH] CWE-787 CVE-2024-0023: In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20452P3HIGHCVSS 7.8v13.0vAndroid-132022-11-08
CVE-2022-20452 [HIGH] CWE-276 CVE-2022-20452: In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code executio In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240138318
nvd
CVE-2024-23708P3HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-23708 [HIGH] CWE-451 CVE-2024-23708: In multiple functions of NotificationManagerService.java, there is a possible way to not show a toas In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31320P3HIGHCVSS 7.8v12.0v12.1+2 more2024-07-09
CVE-2024-31320 [HIGH] CWE-269 CVE-2024-31320: In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion devic In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20142P3HIGHCVSS 7.8v10.0v11.0+3 more2022-06-15
CVE-2022-20142 [HIGH] CVE-2022-20142: In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code ex In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-
nvd
CVE-2023-21275P3HIGHCVSS 7.8v12.0v12.1+4 more2023-08-14
CVE-2023-21275 [HIGH] CVE-2023-21275: In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible wa In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47038P3HIGHCVSS 7.8vAndroid kernel2024-12-18
CVE-2024-47038 [HIGH] CWE-787 CVE-2024-47038: In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds check. This could lead to localcescalation of privilege with no additional execution privileges needed. Usercinteraction is not needed for exploitation.
nvd
CVE-2024-32895P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32895 [HIGH] CWE-787 CVE-2024-32895: In BCMFASTPATH of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds chec In BCMFASTPATH of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9375P3HIGHCVSS 7.8v6.0v6.0.1+6 more2025-01-17
CVE-2018-9375 [HIGH] CWE-269 CVE-2018-9375: In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete word In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21097P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21097 [HIGH] CWE-610 CVE-2023-21097: In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confu In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261858325
nvd
CVE-2024-43768P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-03
CVE-2024-43768 [HIGH] CWE-787 CVE-2024-43768: In skia_alloc_func of SkDeflate.cpp, there is a possible out of bounds write due to an integer overf In skia_alloc_func of SkDeflate.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32909P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32909 [HIGH] CWE-787 CVE-2024-32909: In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. Th In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34741P3HIGHCVSS 7.8v12.0v12.1+6 more2024-08-15
CVE-2024-34741 [HIGH] CWE-269 CVE-2024-34741: In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for messa In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interact
nvd
CVE-2024-0029P3HIGHCVSS 7.8v13.0v132024-02-16
CVE-2024-0029 [HIGH] CWE-693 CVE-2024-0029: In multiple files, there is a possible way to capture the device screen when disallowed by device po In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31326P3HIGHCVSS 7.8v14.0v142024-07-09
CVE-2024-31326 [HIGH] CWE-783 CVE-2024-31326: In multiple locations, there is a possible way in which policy migration code will never be executed In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0051P3HIGHCVSS 7.8v12.0v12.1+6 more2024-03-11
CVE-2024-0051 [HIGH] CWE-787 CVE-2024-0051: In onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer over In onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-45775P3HIGHCVSS 7.8v14.0v142023-12-04
CVE-2023-45775 [HIGH] CWE-787 CVE-2023-45775: In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-45776P3HIGHCVSS 7.8v14.0v142023-12-04
CVE-2023-45776 [HIGH] CWE-787 CVE-2023-45776: In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0018P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-16
CVE-2024-0018 [HIGH] CWE-787 CVE-2024-0018: In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0046P3HIGHCVSS 7.8v12.0v12.1+6 more2024-03-11
CVE-2024-0046 [HIGH] CWE-269 CVE-2024-0046: In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restrictio In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase