cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 79 of 339
CVE-2017-13182P3HIGHCVSS 7.8v8.0v8.12018-01-12
CVE-2017-13182 [HIGH] CWE-190 CVE-2017-13182: In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0,
nvd
CVE-2021-0513P3HIGHCVSS 7.8v8.1v9.0+3 more2021-06-21
CVE-2021-0513 [HIGH] CWE-862 CVE-2021-0513: In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a po In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro
nvd
CVE-2022-20135P3HIGHCVSS 7.8v10.0v11.0+3 more2022-06-15
CVE-2022-20135 [HIGH] CVE-2022-20135: In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220303465
nvd
CVE-2021-0685P3HIGHCVSS 7.8v11.0vAndroid-112021-10-06
CVE-2021-0685 [HIGH] CWE-502 CVE-2021-0685: In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserializati In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-191055353
nvd
CVE-2021-39749P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39749 [HIGH] CWE-862 CVE-2021-39749: In WindowManager, there is a possible way to start non-exported and protected activities due to a mi In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-205996115
nvd
CVE-2017-13289P3HIGHCVSS 7.8v6.0v6.0.1+5 more2018-04-04
CVE-2017-13289 [HIGH] CWE-131 CVE-2017-13289: In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a writ In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size mismatch. This could lead to a local escalation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions
nvd
CVE-2024-34739P3HIGHCVSS 7.8v13.0v14.0+2 more2024-08-15
CVE-2024-34739 [HIGH] CWE-116 CVE-2024-34739: In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escap In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2016-3917P3HIGHCVSS 7.8v6.0.1v7.02016-10-10
CVE-2016-3917 [HIGH] CWE-264 CVE-2016-3917: The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process, which allows physically proximate attackers to authenticate as an arbitrary user by leveraging lockscreen access, aka internal bug 30744668.
nvd
CVE-2023-40109P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-15
CVE-2023-40109 [HIGH] CWE-266 CVE-2023-40109: In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) d In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-0485P3HIGHCVSS 7.8v11.0vAndroid-112021-06-11
CVE-2021-0485 [HIGH] CWE-20 CVE-2021-0485: In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on backgrou In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302616
nvd
CVE-2022-20470P3HIGHCVSS 7.8v10.0v11.0+3 more2022-12-13
CVE-2022-20470 [HIGH] CWE-20 CVE-2022-20470: In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12
nvd
CVE-2023-20911P3HIGHCVSS 7.8v11.0v12.0+3 more2023-03-24
CVE-2023-20911 [HIGH] CWE-400 CVE-2023-20911: In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permi In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Andro
nvd
CVE-2020-0257P3HIGHCVSS 7.8v10.0vAndroid-102020-08-11
CVE-2020-0257 [HIGH] CVE-2020-0257: In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an i In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an incomplete cleanup. This could lead to local escalation of privilege in isolated processes with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-156741968
nvd
CVE-2022-20223P3HIGHCVSS 7.8v10.0v11.0+3 more2022-07-13
CVE-2022-20223 [HIGH] CWE-610 CVE-2022-20223: In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11
nvd
CVE-2021-0652P3HIGHCVSS 7.8v8.1v9.0+3 more2021-10-22
CVE-2021-0652 [HIGH] CWE-362 CVE-2021-0652: In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a mem In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Andr
nvd
CVE-2018-9557P3HIGHCVSS 7.8v7.0v7.1.1+1 more2018-12-06
CVE-2018-9557 [HIGH] CWE-763 CVE-2018-9557: In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninit In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2. Android ID: A-35385357.
nvd
CVE-2019-2049P3HIGHCVSS 7.8v9.0vAndroid-92019-05-08
CVE-2019-2049 [HIGH] CWE-416 CVE-2019-2049: In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption d In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-9 Android ID: A-120445479
nvd
CVE-2019-2033P3HIGHCVSS 7.8v9.02019-04-19
CVE-2019-2033 [HIGH] CWE-416 CVE-2019-2033: In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local es In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-121327565.
nvd
CVE-2022-20478P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20478 [HIGH] CWE-770 CVE-2022-20478: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2022-20479P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20479 [HIGH] CWE-770 CVE-2022-20479: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
Google Android vulnerabilities | cvebase