cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 81 of 339
CVE-2022-39110P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-39110 [HIGH] CWE-862 CVE-2022-39110: In Music service, there is a missing permission check. This could lead to elevation of privilege in In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
nvd
CVE-2022-39108P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-39108 [HIGH] CWE-862 CVE-2022-39108: In Music service, there is a missing permission check. This could lead to elevation of privilege in In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
nvd
CVE-2022-39080P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-39080 [HIGH] CWE-862 CVE-2022-39080: In messaging service, there is a missing permission check. This could lead to elevation of privilege In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
nvd
CVE-2022-39109P3HIGHCVSS 7.8v10.0v11.02022-10-14
CVE-2022-39109 [HIGH] CWE-862 CVE-2022-39109: In Music service, there is a missing permission check. This could lead to elevation of privilege in In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
nvd
CVE-2022-39111P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-14
CVE-2022-39111 [HIGH] CWE-862 CVE-2022-39111: In Music service, there is a missing permission check. This could lead to elevation of privilege in In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
nvd
CVE-2022-20124P3HIGHCVSS 7.8v10.0v11.0+3 more2022-06-15
CVE-2022-20124 [HIGH] CVE-2022-20124: In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre-loaded applications for other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 An
nvd
CVE-2020-0243P3HIGHCVSS 7.8v8.0v8.1+3 more2020-08-11
CVE-2020-0243 [HIGH] CWE-416 CVE-2020-0243: In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper lock In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-8.0 Android-8.1Android ID: A-1
nvd
CVE-2022-39090P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39090 [HIGH] CWE-862 CVE-2022-39090: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39092P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39092 [HIGH] CWE-862 CVE-2022-39092: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39091P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39091 [HIGH] CWE-862 CVE-2022-39091: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2020-0369P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0369 [HIGH] CWE-190 CVE-2020-0369: In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to lo In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-130231426
nvd
CVE-2021-39663P3HIGHCVSS 7.8v10.0vAndroid-102022-02-11
CVE-2021-39663 [HIGH] CWE-610 CVE-2021-39663: In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a pe In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-200682135
nvd
CVE-2022-39095P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39095 [HIGH] CWE-862 CVE-2022-39095: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39101P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39101 [HIGH] CWE-862 CVE-2022-39101: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39096P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39096 [HIGH] CWE-862 CVE-2022-39096: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39099P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39099 [HIGH] CWE-862 CVE-2022-39099: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39102P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39102 [HIGH] CWE-862 CVE-2022-39102: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39094P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39094 [HIGH] CWE-862 CVE-2022-39094: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39100P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39100 [HIGH] CWE-862 CVE-2022-39100: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2021-39674P3HIGHCVSS 7.8v10.0v11.0+2 more2022-02-11
CVE-2021-39674 [HIGH] CWE-416 CVE-2021-39674: In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after fre In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442
nvd
Google Android vulnerabilities | cvebase