cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 70 of 339
CVE-2023-48402P3HIGHCVSS 7.8vAndroid kernel2023-12-08
CVE-2023-48402 [HIGH] CWE-862 CVE-2023-48402: In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could le In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-42740P3HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42740 [HIGH] CWE-862 CVE-2023-42740: In telecom service, there is a possible way to write permission usage records of an app due to a mis In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-42746P3HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42746 [HIGH] CWE-862 CVE-2023-42746: In power manager, there is a possible missing permission check. This could lead to local escalation In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-42739P3HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42739 [HIGH] CWE-862 CVE-2023-42739: In engineermode service, there is a possible way to write permission usage records of an app due to In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-35676P3HIGHCVSS 7.8v12.0v12.1+4 more2023-09-11
CVE-2023-35676 [HIGH] CWE-269 CVE-2023-35676: In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a ba In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35682P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35682 [HIGH] CVE-2023-35682: In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-35665P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35665 [HIGH] CWE-862 CVE-2023-35665: In multiple files, there is a possible way to import a contact from another user due to a missing pe In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35670P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35670 [HIGH] CWE-22 CVE-2023-35670: In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' e In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21254P3HIGHCVSS 7.8v13.0v132023-07-13
CVE-2023-21254 [HIGH] CWE-863 CVE-2023-21254: In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time pe In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21192P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2023-21192 [HIGH] CWE-20 CVE-2023-21192: In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to s In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1
nvd
CVE-2023-21081P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21081 [HIGH] CVE-2023-21081: In multiple functions of PackageInstallerService.java and related files, there is a possible way to In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11
nvd
CVE-2024-20015P3HIGHCVSS 7.8v12.0v13.0+1 more2024-02-05
CVE-2024-20015 [HIGH] CWE-305 CVE-2024-20015: In telephony, there is a possible escalation of privilege due to a permissions bypass. This could le In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441419; Issue ID: ALPS08441419.
nvd
CVE-2023-21100P3HIGHCVSS 7.8v12.0v12.1+2 more2023-04-19
CVE-2023-21100 [HIGH] CWE-787 CVE-2023-21100: In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-242544249
nvd
CVE-2023-20985P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-20985 [HIGH] CWE-787 CVE-2023-20985: In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245915315
nvd
CVE-2023-21022P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21022 [HIGH] CWE-787 CVE-2023-21022: In BufferBlock of Suballocation.cpp, there is a possible out of bounds write due to memory corruptio In BufferBlock of Suballocation.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236098131
nvd
CVE-2023-20936P3HIGHCVSS 7.8v11.0v12.0+3 more2023-03-24
CVE-2023-20936 [HIGH] CWE-787 CVE-2023-20936: In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bo In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-226927612
nvd
CVE-2023-21372P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21372 [HIGH] CWE-125 CVE-2023-21372: In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21245P3HIGHCVSS 7.8v11.0v12.0+6 more2023-07-13
CVE-2023-21245 [HIGH] CWE-863 CVE-2023-21245: In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible w In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20975P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-20975 [HIGH] CWE-863 CVE-2023-20975: In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way t In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android I
nvd
CVE-2025-20668P3HIGHCVSS 7.8v14.0v15.02025-05-05
CVE-2025-20668 [HIGH] CWE-787 CVE-2025-20668: In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027.
nvd
Google Android vulnerabilities | cvebase