cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 80 of 339
CVE-2022-20491P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20491 [HIGH] CWE-1284 CVE-2022-20491: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-
nvd
CVE-2022-20495P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20495 [HIGH] CWE-276 CVE-2022-20495: In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 An
nvd
CVE-2020-0440P3HIGHCVSS 7.8v11.0vAndroid-112020-12-14
CVE-2020-0440 [HIGH] CWE-862 CVE-2020-0440: In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted v In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162627132
nvd
CVE-2022-20484P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20484 [HIGH] CWE-770 CVE-2022-20484: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2022-20480P3HIGHCVSS 7.8v10.0v11.0+4 more2022-12-13
CVE-2022-20480 [HIGH] CWE-770 CVE-2022-20480: In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissio In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-1
nvd
CVE-2020-0115P3HIGHCVSS 7.8v8.0v8.1+3 more2020-06-10
CVE-2020-0115 [HIGH] CWE-863 CVE-2020-0115: In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass al In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Andr
nvd
CVE-2021-0310P3HIGHCVSS 7.8v11.0vAndroid-112021-01-11
CVE-2021-0310 [HIGH] CWE-416 CVE-2021-0310: In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Android ID: A-170212632.
nvd
CVE-2020-0275P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0275 [HIGH] CWE-276 CVE-2020-0275: In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app s In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass. This could lead to local escalation of privilege, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150507
nvd
CVE-2021-39626P3HIGHCVSS 7.8v9.0v10.0+3 more2022-01-14
CVE-2021-39626 [HIGH] CWE-610 CVE-2021-39626: In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9
nvd
CVE-2020-0046P3HIGHCVSS 7.8v10.0vAndroid-102020-03-10
CVE-2020-0046 [HIGH] CWE-787 CVE-2020-0046: In DrmPlugin::releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a In DrmPlugin::releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137284652
nvd
CVE-2022-20506P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20506 [HIGH] CWE-862 CVE-2022-20506: In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to loca In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226133034
nvd
CVE-2022-38670P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-38670 [HIGH] CWE-862 CVE-2022-38670: In soundrecorder service, there is a missing permission check. This could lead to elevation of privi In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
nvd
CVE-2022-2985P3HIGHCVSS 7.8v10.0v11.02022-10-14
CVE-2022-2985 [HIGH] CWE-862 CVE-2022-2985: In music service, there is a missing permission check. This could lead to elevation of privilege in In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
nvd
CVE-2022-38669P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-38669 [HIGH] CWE-862 CVE-2022-38669: In soundrecorder service, there is a missing permission check. This could lead to elevation of privi In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
nvd
CVE-2020-0346P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0346 [HIGH] CWE-190 CVE-2020-0346: In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if integer sanitization were not enabled (which it is by default), with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147002762
nvd
CVE-2019-9407P3HIGHCVSS 7.8v10.0vAndroid-102019-09-27
CVE-2019-9407 [HIGH] CVE-2019-9407: In notification management of the service manager, there is a possible permissions bypass. This coul In notification management of the service manager, there is a possible permissions bypass. This could lead to local escalation of privilege by preventing user notification, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112434609
nvd
CVE-2022-20522P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20522 [HIGH] CWE-862 CVE-2022-20522: In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to loca In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227470877
nvd
CVE-2020-0120P3HIGHCVSS 7.8v10.0vAndroid-102020-07-17
CVE-2020-0120 [HIGH] CWE-787 CVE-2020-0120: In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-149995442
nvd
CVE-2022-38698P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-38698 [HIGH] CWE-862 CVE-2022-38698: In messaging service, there is a missing permission check. This could lead to elevation of privilege In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
nvd
CVE-2022-39107P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-39107 [HIGH] CWE-862 CVE-2022-39107: In Soundrecorder service, there is a missing permission check. This could lead to elevation of privi In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.
nvd
Google Android vulnerabilities | cvebase