Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 70 of 483
CVE-2024-27229HIGHCVSS 7.5v132024-03-11
CVE-2024-27229 [HIGH] CWE-476 CVE-2024-27229: In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref d In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27220HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27220 [HIGH] CWE-125 CVE-2024-27220: In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds chec In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27221HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27221 [HIGH] CWE-787 CVE-2024-27221: In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. Th In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23717HIGHCVSS 8.8v12.0v12.1+6 more2024-03-11
CVE-2024-23717 [HIGH] CWE-20 CVE-2024-23717: In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-0046HIGHCVSS 7.8v12.0v12.1+6 more2024-03-11
CVE-2024-0046 [HIGH] CWE-269 CVE-2024-0046: In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restrictio In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-27222HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27222 [HIGH] CWE-269 CVE-2024-27222: In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27224HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27224 [HIGH] CWE-269 CVE-2024-27224: In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27204HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27204 [HIGH] CWE-787 CVE-2024-27204: In tmu_set_gov_active of tmu.c, there is a possible out of bounds write due to a missing bounds chec In tmu_set_gov_active of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-22007MEDIUMCVSS 6.2v13.0v132024-03-11
CVE-2024-22007 [MEDIUM] CWE-125 CVE-2024-22007: In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27234MEDIUMCVSS 5.9v13.0v132024-03-11
CVE-2024-27234 [MEDIUM] CWE-125 CVE-2024-27234: In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. Th In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0044MEDIUMCVSS 6.7v12.0v12.1+7 more2024-03-11
CVE-2024-0044 [MEDIUM] CWE-74 CVE-2024-0044: In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-27225MEDIUMCVSS 4.4v13.0v132024-03-11
CVE-2024-27225 [MEDIUM] CWE-120 CVE-2024-27225: In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer o In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-25984MEDIUMCVSS 6.2v13.0v132024-03-11
CVE-2024-25984 [MEDIUM] CWE-120 CVE-2024-25984: In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-22006MEDIUMCVSS 5.3v13.0v132024-03-11
CVE-2024-22006 [MEDIUM] CWE-125 CVE-2024-22006: OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of th OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.
nvd
CVE-2024-25987MEDIUMCVSS 6.7v13.0v132024-03-11
CVE-2024-25987 [MEDIUM] CWE-269 CVE-2024-25987: In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds che In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-22010MEDIUMCVSS 5.5v13.0v132024-03-11
CVE-2024-22010 [MEDIUM] CWE-125 CVE-2024-22010: In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0047MEDIUMCVSS 5.5v14.0v142024-03-11
CVE-2024-0047 [MEDIUM] CWE-502 CVE-2024-0047: In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-27230MEDIUMCVSS 5.1v13.0v132024-03-11
CVE-2024-27230 [MEDIUM] CWE-125 CVE-2024-27230: In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2024-0045MEDIUMCVSS 6.5v12.0v12.1+6 more2024-03-11
CVE-2024-0045 [MEDIUM] CWE-125 CVE-2024-0045: In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input vali In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-27235MEDIUMCVSS 5.5v13.0v132024-03-11
CVE-2024-27235 [MEDIUM] CWE-125 CVE-2024-27235: In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. Thi In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd