cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 67 of 339
CVE-2021-25407P3HIGHCVSS 7.8v9.0v10.0+1 more2021-06-11
CVE-2021-25407 [HIGH] CWE-787 CVE-2021-25407: A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows ar A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.
nvd
CVE-2021-0307P3HIGHCVSS 7.8v10.0v11.0+2 more2021-01-11
CVE-2021-0307 [HIGH] CVE-2021-0307: In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic run In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. This could lead to local escalation of privilege allowing a malicious app to silently gain access to a dangerous permission with no additional execution privileges needed. User interaction is not needed for exploita
nvd
CVE-2022-26469P3HIGHCVSS 7.8v11.0v12.02022-09-06
CVE-2022-26469 [HIGH] CWE-470 CVE-2022-26469: In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07216598; Issue ID: ALPS07216598.
nvd
CVE-2022-20113P3HIGHCVSS 7.8v12.0v12.1+1 more2022-05-10
CVE-2022-20113 [HIGH] CVE-2022-20113: In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enabl In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A
nvd
CVE-2019-2123P3HIGHCVSS 7.8v7.1.1v7.1.2+4 more2019-09-05
CVE-2019-2123 [HIGH] CWE-787 CVE-2019-2123: In execTransact of Binder.java in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible local e In execTransact of Binder.java in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible local execution of arbitrary code in a privileged process due to a memory overwrite. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21094P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21094 [HIGH] CWE-862 CVE-2023-21094: In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12
nvd
CVE-2022-20503P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20503 [HIGH] CWE-862 CVE-2022-20503: In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a W In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-22477
nvd
CVE-2023-35687P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35687 [HIGH] CWE-416 CVE-2023-35687: In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-42544P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-42544 [HIGH] CWE-74 CVE-2022-42544: In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224545390
nvd
CVE-2022-20133P3HIGHCVSS 7.8v10.0v11.0+3 more2022-06-15
CVE-2022-20133 [HIGH] CWE-862 CVE-2022-20133: In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-2
nvd
CVE-2022-20416P3HIGHCVSS 7.8v12.0v12.1+2 more2022-10-11
CVE-2022-20416 [HIGH] CWE-787 CVE-2022-20416: In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrec In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237717857
nvd
CVE-2022-26092P3HIGHCVSS 7.8v10.0v11.0+1 more2022-04-11
CVE-2022-26092 [HIGH] CWE-122 CVE-2022-26092: Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.
nvd
CVE-2022-20462P3HIGHCVSS 7.8v10.0v11.0+4 more2022-11-08
CVE-2022-20462 [HIGH] CWE-787 CVE-2022-20462: In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a mi In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android
nvd
CVE-2023-21109P3HIGHCVSS 7.8v11.0v12.0+3 more2023-05-15
CVE-2023-21109 [HIGH] CWE-326 CVE-2023-21109: In multiple places of AccessibilityService, there is a possible way to hide the app from the user du In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Androi
nvd
CVE-2023-20916P3HIGHCVSS 7.8v12.0v12.1+1 more2023-01-26
CVE-2023-20916 [HIGH] CWE-862 CVE-2023-20916: In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the re In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer
nvd
CVE-2023-20912P3HIGHCVSS 7.8v13.0vAndroid-132023-01-26
CVE-2023-20912 [HIGH] CWE-862 CVE-2023-20912: In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-2463019
nvd
CVE-2022-20550P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20550 [HIGH] CWE-610 CVE-2022-20550: In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a conf In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-242845514
nvd
CVE-2021-0427P3HIGHCVSS 7.8v11.0vAndroid-112021-04-13
CVE-2021-0427 [HIGH] CWE-787 CVE-2021-0427: In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a h In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174488848
nvd
CVE-2023-32837P3HIGHCVSS 7.8v12.02023-11-06
CVE-2023-32837 [HIGH] CWE-787 CVE-2023-32837: In video, there is a possible out of bounds write due to a missing bounds check. This could lead to In video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08250357.
nvd
CVE-2021-0426P3HIGHCVSS 7.8v11.0vAndroid-112021-04-13
CVE-2021-0426 [HIGH] CWE-787 CVE-2021-0426: In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174485572
nvd
Google Android vulnerabilities | cvebase