cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 68 of 339
CVE-2022-24931P3HIGHCVSS 7.8v10.0v11.02022-03-10
CVE-2022-24931 [HIGH] CWE-269 CVE-2022-24931: Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Rele Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbitrary activity without a proper permission
nvd
CVE-2023-21351P3HIGHCVSS 7.8v14.0v13+2 more2023-10-30
CVE-2023-21351 [HIGH] CVE-2023-21351: In multiple locations, there is a possible background activity launch due to a logic error in the co In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21398P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21398 [HIGH] CVE-2023-21398: In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20508P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20508 [HIGH] CWE-862 CVE-2022-20508: In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi s In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-218679614
nvd
CVE-2023-21266P3HIGHCVSS 7.8v11.0v12.0+5 more2023-10-06
CVE-2023-21266 [HIGH] CVE-2023-21266: In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-39853P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-07
CVE-2022-39853 [HIGH] CWE-416 CVE-2022-39853: A use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to A use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2021-39662P3HIGHCVSS 7.8v11.0v12.0+1 more2022-02-11
CVE-2021-39662 [HIGH] CWE-862 CVE-2021-39662: In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Androi
nvd
CVE-2024-31310P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31310 [HIGH] CWE-20 CVE-2024-31310: In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabl In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-23729P3HIGHCVSS 7.8fixed in 11.02022-03-04
CVE-2022-23729 [HIGH] CWE-305 CVE-2022-23729: When the device is in factory state, it can be access the shell without adb authentication process. When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.
nvd
CVE-2023-48407P3HIGHCVSS 7.8vAndroid kernel2023-12-08
CVE-2023-48407 [HIGH] CVE-2023-48407: there is a possible DCK won't be deleted after factory reset due to a logic error in the code. This there is a possible DCK won't be deleted after factory reset due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-39759P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39759 [HIGH] CWE-190 CVE-2021-39759: In libstagefright, there is a possible out of bounds write due to an integer overflow. This could le In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-180200830
nvd
CVE-2022-20099P3HIGHCVSS 7.8v11.0v12.02022-05-03
CVE-2022-20099 [HIGH] CWE-787 CVE-2022-20099: In aee daemon, there is a possible out of bounds write due to improper input validation. This could In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296442.
nvd
CVE-2021-0630P3HIGHCVSS 7.5v8.1v9.0+2 more2021-10-25
CVE-2021-0630 [HIGH] CWE-190 CVE-2021-0630: In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to r In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05551397; Issue ID: ALPS05551397.
nvd
CVE-2021-0631P3HIGHCVSS 7.5v8.1v9.0+2 more2021-10-25
CVE-2021-0631 [HIGH] CWE-125 CVE-2021-0631: In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to r In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05551435; Issue ID: ALPS05551435.
nvd
CVE-2024-32892P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32892 [HIGH] CWE-843 CVE-2024-32892: In handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. T In handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21396P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21396 [HIGH] CWE-269 CVE-2023-21396: In Activity Manager, there is a possible background activity launch due to a logic error in the code In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21122P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21122 [HIGH] CWE-862 CVE-2023-21122: In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEAT In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android
nvd
CVE-2023-21124P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21124 [HIGH] CWE-502 CVE-2023-21124: In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-265798353
nvd
CVE-2023-21123P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21123 [HIGH] CWE-862 CVE-2023-21123: In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FE In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Andro
nvd
CVE-2022-20420P3HIGHCVSS 7.8v13.0vAndroid-132022-10-11
CVE-2022-20420 [HIGH] CVE-2022-20420: In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way to bypass device policy restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android
nvd
Google Android vulnerabilities | cvebase