cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 77 of 339
CVE-2019-2222P3HIGHCVSS 7.8v8.0v8.1+3 more2019-12-06
CVE-2019-2222 [HIGH] CWE-787 CVE-2019-2222: n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140322595
nvd
CVE-2019-2223P3HIGHCVSS 7.8v8.0v8.1+3 more2019-12-06
CVE-2019-2223 [HIGH] CWE-787 CVE-2019-2223: In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bo In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140692129
nvd
CVE-2020-0108P3HIGHCVSS 7.8v8.1v9.0+2 more2020-08-11
CVE-2020-0108 [HIGH] CWE-755 CVE-2020-0108: In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrict In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-140
nvd
CVE-2018-9565P3HIGHCVSS 7.5v9.02018-12-06
CVE-2018-9565 [HIGH] CWE-125 CVE-2018-9565: In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. Th In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.
nvd
CVE-2021-0928P3HIGHCVSS 7.8v9.0v10.0+2 more2021-12-15
CVE-2021-0928 [HIGH] CWE-20 CVE-2021-0928: In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserializ In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Andro
nvd
CVE-2021-39787P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39787 [HIGH] CWE-610 CVE-2021-39787: In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-202506934
nvd
CVE-2020-0114P3HIGHCVSS 7.8v10.0vAndroid-102020-06-10
CVE-2020-0114 [HIGH] CVE-2020-0114: In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID:
nvd
CVE-2020-0441P3HIGHCVSS 7.5v8.0v8.1+4 more2020-11-10
CVE-2020-0441 [HIGH] CWE-400 CVE-2020-0441: In Message and toBundle of Notification.java, there is a possible resource exhaustion due to imprope In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service requiring a device reset to fix with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 An
nvd
CVE-2015-6612P3CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-11-03
CVE-2015-6612 [CRITICAL] CWE-264 CVE-2015-6612: libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privilege libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 23540426.
nvd
CVE-2024-23705P3HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-23705 [HIGH] CWE-20 CVE-2024-23705: In multiple locations, there is a possible failure to persist or enforce user restrictions due to im In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2020-0401P3HIGHCVSS 7.8v8.0v8.1+3 more2020-09-17
CVE-2020-0401 [HIGH] CWE-862 CVE-2020-0401: In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11A
nvd
CVE-2022-20489P3HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20489 [HIGH] CWE-770 CVE-2022-20489: In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions setti In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Andro
nvd
CVE-2020-0226P3HIGHCVSS 7.8v10.0vAndroid-102020-07-17
CVE-2020-0226 [HIGH] CWE-787 CVE-2020-0226: In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confus In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150226994
nvd
CVE-2019-2052P3HIGHCVSS 7.5v7.0v7.1.1+4 more2019-05-08
CVE-2019-2052 [HIGH] CWE-125 CVE-2019-2052: In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This coul In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.1 Android-9 Android ID: A-117556606
nvd
CVE-2020-0394P3HIGHCVSS 7.8v8.0v8.1+3 more2020-09-17
CVE-2020-0394 [HIGH] CWE-1021 CVE-2020-0394: In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 A
nvd
CVE-2022-20492P3HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20492 [HIGH] CWE-770 CVE-2022-20492: In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions setti In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Andro
nvd
CVE-2022-20490P3HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20490 [HIGH] CWE-770 CVE-2022-20490: In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions s In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L A
nvd
CVE-2020-0392P3HIGHCVSS 7.8v9.0v10.0+1 more2020-09-17
CVE-2020-0392 [HIGH] CWE-415 CVE-2020-0392: In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-150226608
nvd
CVE-2021-0589P3HIGHCVSS 7.8v8.1v9.0+3 more2021-07-14
CVE-2021-0589 [HIGH] CWE-787 CVE-2021-0589: In BTM_TryAllocateSCN of btm_scn.cc, there is a possible out of bounds write due to an incorrect bou In BTM_TryAllocateSCN of btm_scn.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-180939982
nvd
CVE-2021-0327P3HIGHCVSS 7.8v8.1v9.0+3 more2021-02-10
CVE-2021-0327 [HIGH] CWE-269 CVE-2021-0327: In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android
nvd
Google Android vulnerabilities | cvebase