cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 85 of 339
CVE-2021-0439P3HIGHCVSS 7.8v11.0vAndroid-112021-04-13
CVE-2021-0439 [HIGH] CWE-787 CVE-2021-0439: In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible o In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174243830
nvd
CVE-2021-0442P3HIGHCVSS 7.8v11.0vAndroid-112021-04-13
CVE-2021-0442 [HIGH] CWE-416 CVE-2021-0442: In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of c In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174768985
nvd
CVE-2022-20031P3HIGHCVSS 7.8v10.0v11.02022-02-09
CVE-2022-20031 [HIGH] CWE-416 CVE-2022-20031: In fb driver, there is a possible memory corruption due to a use after free. This could lead to loca In fb driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05850708; Issue ID: ALPS05850708.
nvd
CVE-2024-31315P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31315 [HIGH] CWE-266 CVE-2024-31315: In multiple functions of ManagedServices.java, there is a possible way to hide an app with notificat In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-0550P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0550 [HIGH] CWE-610 CVE-2021-0550: In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE per In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without user consent due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-1796
nvd
CVE-2023-21337P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21337 [HIGH] CWE-203 CVE-2023-21337: In InputMethod, there is a possible way to determine whether an app is installed, without query perm In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20441P3HIGHCVSS 7.8v10.0v11.0+4 more2022-11-08
CVE-2022-20441 [HIGH] CWE-276 CVE-2022-20441: In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10
nvd
CVE-2021-1003P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-1003 [HIGH] CWE-610 CVE-2021-1003: In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change a In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189857506
nvd
CVE-2021-0981P3HIGHCVSS 7.8v10.0v11.0+1 more2021-12-15
CVE-2021-0981 [HIGH] CVE-2021-0981: In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a foreground service without showing a notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1
nvd
CVE-2021-0610P3HIGHCVSS 7.8v10.0v11.02021-09-27
CVE-2021-0610 [HIGH] CWE-190 CVE-2021-0610: In memory management driver, there is a possible memory corruption due to an integer overflow. This In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05411456.
nvd
CVE-2022-20114P3HIGHCVSS 7.8v10.0v11.0+3 more2022-05-10
CVE-2022-20114 [HIGH] CWE-269 CVE-2022-20114: In placeCall of TelecomManager.java, there is a possible way for an application to keep itself runni In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Andr
nvd
CVE-2021-39799P3HIGHCVSS 7.8v12.0v12.1+1 more2022-04-12
CVE-2021-39799 [HIGH] CWE-863 CVE-2021-39799: In AttributionSource of AttributionSource.java, there is a possible permission bypass due to imprope In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-200288596
nvd
CVE-2021-0926P3HIGHCVSS 7.8v9.0v10.0+3 more2021-12-15
CVE-2021-0926 [HIGH] CWE-862 CVE-2021-0926: In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9
nvd
CVE-2022-48384P3HIGHCVSS 7.8v10.0v11.0+2 more2023-05-09
CVE-2022-48384 [HIGH] CWE-862 CVE-2022-48384: In srtd service, there is a possible missing permission check. This could lead to local escalation o In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-20547P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20547 [HIGH] CWE-862 CVE-2022-20547: In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240301753
nvd
CVE-2021-39797P3HIGHCVSS 7.8v12.0v12.1+1 more2022-04-12
CVE-2021-39797 [HIGH] CWE-269 CVE-2021-39797: In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a l In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-209607104
nvd
CVE-2021-0388P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0388 [HIGH] CWE-862 CVE-2021-0388: In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler. This could lead to local escalation of privilege resulting in attributing video call data to the wrong app, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi
nvd
CVE-2021-0385P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0385 [HIGH] CWE-862 CVE-2021-0385: In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connection to untrusted WiFi networks due to notification interaction above the lockscreen. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc
nvd
CVE-2021-0380P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0380 [HIGH] CWE-862 CVE-2021-0380: In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify oth In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission check. This could lead to local escalation of privilege during the onboarding flow with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2022-20395P3HIGHCVSS 7.8v11.0v12.0+3 more2022-09-13
CVE-2022-20395 [HIGH] CWE-22 CVE-2022-20395: In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal erro In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-221855295
nvd
Google Android vulnerabilities | cvebase