cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 82 of 339
CVE-2020-27030P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-27030 [HIGH] CVE-2020-27030: In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. In onCreate of HandleApiCalls.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege that allows an app to set or dismiss the alarm with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150612638
nvd
CVE-2022-20026P3HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20026 [HIGH] CWE-787 CVE-2022-20026: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126827; Issue ID: ALPS06126827.
nvd
CVE-2022-20027P3HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20027 [HIGH] CWE-787 CVE-2022-20027: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126826; Issue ID: ALPS06126826.
nvd
CVE-2022-20025P3HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20025 [HIGH] CWE-787 CVE-2022-20025: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126832; Issue ID: ALPS06126832.
nvd
CVE-2022-20028P3HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20028 [HIGH] CWE-787 CVE-2022-20028: In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198663; Issue ID: ALPS06198663.
nvd
CVE-2021-0959P3HIGHCVSS 7.8v12.0vAndroid-122022-01-14
CVE-2021-0959 [HIGH] CVE-2021-0959: In jit_memory_region.cc, there is a possible bypass of memory restrictions due to a logic error in t In jit_memory_region.cc, there is a possible bypass of memory restrictions due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-200284993
nvd
CVE-2022-39098P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39098 [HIGH] CWE-862 CVE-2022-39098: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2022-39097P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39097 [HIGH] CWE-862 CVE-2022-39097: In power management service, there is a missing permission check. This could lead to set up power ma In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2021-0708P3HIGHCVSS 7.8v8.1v9.0+3 more2021-10-22
CVE-2021-0708 [HIGH] CWE-610 CVE-2021-0708: In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-1832
nvd
CVE-2022-26472P3HIGHCVSS 7.8v10.0v11.0+1 more2022-10-07
CVE-2022-26472 [HIGH] CWE-502 CVE-2022-26472: In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319095; Issue ID: ALPS07319095.
nvd
CVE-2022-20477P3HIGHCVSS 7.8v13.0vAndroid-132022-12-13
CVE-2022-20477 [HIGH] CWE-783 CVE-2022-20477: In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to s In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A
nvd
CVE-2022-20144P3HIGHCVSS 7.8v10.0v11.0+1 more2022-06-15
CVE-2022-20144 [HIGH] CVE-2022-20144: In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-25063
nvd
CVE-2023-20919P3HIGHCVSS 7.8v13.0vAndroid-132023-01-26
CVE-2023-20919 [HIGH] CWE-693 CVE-2023-20919: In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation du In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-252663068
nvd
CVE-2021-0602P3HIGHCVSS 7.8v10.0v11.0+1 more2021-07-14
CVE-2021-0602 [HIGH] CWE-200 CVE-2021-0602: In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users t In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi-Fi settings for all configured APs due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2021-0587P3HIGHCVSS 7.8v8.1v9.0+3 more2021-07-14
CVE-2021-0587 [HIGH] CWE-416 CVE-2021-0587: In StreamOut::prepareForWriting of StreamOut.cpp, there is a possible out of bounds write due to a u In StreamOut::prepareForWriting of StreamOut.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185259758
nvd
CVE-2022-20512P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20512 [HIGH] CWE-20 CVE-2022-20512: In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238602879
nvd
CVE-2020-0417P3HIGHCVSS 7.8v8.1v9.0+2 more2021-07-14
CVE-2020-0417 [HIGH] CWE-732 CVE-2020-0417: In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to a In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-154319182
nvd
CVE-2023-20920P3HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2023-20920 [HIGH] CWE-416 CVE-2023-20920: In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-204584366
nvd
CVE-2023-20905P3HIGHCVSS 7.8v10.0vAndroid-102023-01-26
CVE-2023-20905 [HIGH] CWE-787 CVE-2023-20905: In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a miss In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-241387741
nvd
CVE-2022-20043P3HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20043 [HIGH] CWE-862 CVE-2022-20043: In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This co In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06148177; Issue ID: ALPS06148177.
nvd
Google Android vulnerabilities | cvebase