cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 54 of 339
CVE-2024-43762P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-03
CVE-2024-43762 [HIGH] CVE-2024-43762: In multiple locations, there is a possible way to avoid unbinding of a service from the system due t In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-27024P3HIGHCVSS 7.5v11.0vAndroid-112020-12-15
CVE-2020-27024 [HIGH] CWE-125 CVE-2020-27024: In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds read due to a mis In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure triggered by a malformed Bluetooth packet, with no additional execution privileges needed. User interaction is not needed for exploitation. Bounds Sanitizer mitigates this in the defaul
nvd
CVE-2024-47040P3HIGHCVSS 7.8vAndroid Kernel2024-12-18
CVE-2024-47040 [HIGH] CWE-416 CVE-2024-47040: There is a possible UAF due to a logic error in the code. This could lead to local escalation of pri There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21286P3HIGHCVSS 7.8v11.0v12.0+6 more2023-08-14
CVE-2023-21286 [HIGH] CVE-2023-21286: In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a mis In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43088P3HIGHCVSS 7.8v12.0v12.1+8 more2024-11-13
CVE-2024-43088 [HIGH] CWE-862 CVE-2024-43088: In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission sett In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20507P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20507 [HIGH] CWE-20 CVE-2022-20507: In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246649179
nvd
CVE-2022-20540P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20540 [HIGH] CWE-416 CVE-2022-20540: In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-237291506
nvd
CVE-2024-31319P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31319 [HIGH] CWE-610 CVE-2024-31319: In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a po In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20524P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20524 [HIGH] CWE-416 CVE-2022-20524: In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. Th In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228523213
nvd
CVE-2018-9471P3HIGHCVSS 7.8v7.0v7.1.1+9 more2024-11-20
CVE-2018-9471 [HIGH] CWE-843 CVE-2018-9471: In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to ty In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21272P3HIGHCVSS 7.8v11.0v12.0+4 more2023-08-14
CVE-2023-21272 [HIGH] CWE-20 CVE-2023-21272: In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validati In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32900P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32900 [HIGH] CWE-416 CVE-2024-32900: In lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. Th In lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. This could lead to local escalation of privilege from hal_camera_default SELinux label with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0438P3HIGHCVSS 7.8v10.0v11.0+1 more2020-11-10
CVE-2020-0438 [HIGH] CWE-824 CVE-2020-0438: In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due t In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr
nvd
CVE-2023-40103P3HIGHCVSS 7.8v14.0v142023-12-04
CVE-2023-40103 [HIGH] CWE-415 CVE-2023-40103: In multiple locations, there is a possible way to corrupt memory due to a double free. This could le In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0033P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-16
CVE-2024-0033 [HIGH] CWE-787 CVE-2024-0033: In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overf In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-2194P3HIGHCVSS 7.8v9.0vAndroid-92020-10-14
CVE-2019-2194 [HIGH] CWE-704 CVE-2019-2194: In SurfaceFlinger::createLayer of SurfaceFlinger.cpp, there is a possible arbitrary code execution d In SurfaceFlinger::createLayer of SurfaceFlinger.cpp, there is a possible arbitrary code execution due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-137284057
nvd
CVE-2022-23428P3HIGHCVSS 7.8v10.0v11.0+1 more2022-02-11
CVE-2022-23428 [HIGH] CWE-120 CVE-2022-23428: An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitr An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2023-35685P3HIGHCVSS 7.8vAndroid SoC2025-01-08
CVE-2023-35685 [HIGH] CWE-416 CVE-2023-35685: In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic err In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21342P3HIGHCVSS 7.8v13.0v132023-10-30
CVE-2023-21342 [HIGH] CVE-2023-21342: In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-27836P3HIGHCVSS 7.8v12.02022-04-11
CVE-2022-27836 [HIGH] CWE-284 CVE-2022-27836: Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Serv Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.
nvd
Google Android vulnerabilities | cvebase