cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 78 of 339
CVE-2021-0336P3HIGHCVSS 7.8v8.1v9.0+3 more2021-02-10
CVE-2021-0336 [HIGH] CWE-732 CVE-2021-0336: In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mut In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android
nvd
CVE-2021-0306P3HIGHCVSS 7.8v8.0v8.1+8 more2021-01-11
CVE-2021-0306 [HIGH] CWE-269 CVE-2021-0306: In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when u In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction
nvd
CVE-2021-0318P3HIGHCVSS 7.8v8.1v9.0+6 more2021-01-11
CVE-2021-0318 [HIGH] CWE-416 CVE-2021-0318: In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write d In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-8.1, Android-10, Android-11; Android I
nvd
CVE-2021-0478P3HIGHCVSS 7.8v8.1v9.0+3 more2021-06-21
CVE-2021-0478 [HIGH] CWE-755 CVE-2021-0478: In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaugh In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services without notifying the user, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11
nvd
CVE-2020-0409P3HIGHCVSS 7.8v8.0v8.1+3 more2020-11-10
CVE-2020-0409 [HIGH] CWE-190 CVE-2020-0409: In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This c In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-156997193
nvd
CVE-2020-0203P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0203 [HIGH] CWE-404 CVE-2020-0203: In freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. In freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. This could lead to local escalation of privilege between constrained processes with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146313311
nvd
CVE-2020-0136P3HIGHCVSS 7.8v10.0vAndroid-102020-06-11
CVE-2020-0136 [HIGH] CWE-190 CVE-2020-0136: In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overf In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-120078455
nvd
CVE-2020-0242P3HIGHCVSS 7.8v8.0v8.1+3 more2020-08-11
CVE-2020-0242 [HIGH] CWE-416 CVE-2020-0242: In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This cou In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151643722
nvd
CVE-2021-0332P3HIGHCVSS 7.8v10.0v11.0+1 more2021-02-10
CVE-2021-0332 [HIGH] CWE-416 CVE-2021-0332: In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-169256435
nvd
CVE-2022-20456P3HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20456 [HIGH] CWE-770 CVE-2022-20456: In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions set In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L And
nvd
CVE-2021-0390P3HIGHCVSS 7.8v8.1v9.0+3 more2021-03-10
CVE-2021-0390 [HIGH] CWE-862 CVE-2021-0390: In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of sugges In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. This could lead to local escalation of privilege by a background user on the same device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio
nvd
CVE-2021-0328P3HIGHCVSS 7.8v8.1v9.0+3 more2021-02-10
CVE-2021-0328 [HIGH] CWE-862 CVE-2021-0328: In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android
nvd
CVE-2021-0683P3HIGHCVSS 7.8v8.1v9.0+3 more2021-10-06
CVE-2021-0683 [HIGH] CVE-2021-0683: In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-18539894
nvd
CVE-2021-0510P3HIGHCVSS 7.8v8.1v9.0+3 more2021-06-21
CVE-2021-0510 [HIGH] CWE-190 CVE-2021-0510: In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overfl In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444622
nvd
CVE-2021-0640P3HIGHCVSS 7.8v9.0v10.0+2 more2021-08-17
CVE-2021-0640 [HIGH] CWE-787 CVE-2021-0640: In noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bound In noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-187957589
nvd
CVE-2022-20005P3HIGHCVSS 7.8v10.0v11.0+3 more2022-05-10
CVE-2022-20005 [HIGH] CVE-2022-20005: In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch betw In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-21904
nvd
CVE-2020-0439P3HIGHCVSS 7.8v8.0v8.1+4 more2020-11-10
CVE-2020-0439 [HIGH] CWE-862 CVE-2020-0439: In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant apps, with no additional execution privileges needed. User interaction is not needed for exploitation.Pro
nvd
CVE-2021-0595P3HIGHCVSS 7.8v8.1v9.0+3 more2021-10-06
CVE-2021-0595 [HIGH] CWE-287 CVE-2021-0595: In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profi In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Androi
nvd
CVE-2022-20004P3HIGHCVSS 7.8v10.0v11.0+3 more2022-05-10
CVE-2022-20004 [HIGH] CWE-862 CVE-2022-20004: In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to i In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID:
nvd
CVE-2021-0472P3HIGHCVSS 7.8v9.0v10.0+2 more2021-06-11
CVE-2021-0472 [HIGH] CWE-863 CVE-2021-0472: In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning withou In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-17
nvd
Google Android vulnerabilities | cvebase