Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 93 of 339
CVE-2023-21358P3HIGHCVSS 7.8v14.0v142023-10-30
CVE-2023-21358 [HIGH] CWE-295 CVE-2023-21358: In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.u
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40634P3HIGHCVSS 7.8v11.0v12.0+1 more2023-10-08
CVE-2023-40634 [HIGH] CWE-862 CVE-2023-40634: In phasechecksercer, there is a possible missing permission check. This could lead to local escalati
In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-40635P3HIGHCVSS 7.8v11.02023-10-08
CVE-2023-40635 [HIGH] CWE-862 CVE-2023-40635: In linkturbo, there is a possible missing permission check. This could lead to local escalation of p
In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-21000P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21000 [HIGH] CWE-667 CVE-2023-21000: In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to lo
In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194783918
nvd
CVE-2018-9432P3HIGHCVSS 7.8v6.0v6.0.1+10 more2024-11-19
CVE-2018-9432 [HIGH] CWE-276 CVE-2018-9432: In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a
In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing the user's ability to disable access to contacts, with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2019-9234P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9234 [HIGH] CWE-125 CVE-2019-9234: In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This coul
In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122465453
nvd
CVE-2019-9233P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9233 [HIGH] CWE-125 CVE-2019-9233: In wpa_supplicant_8, there is a possible out of bounds read due to an incorrect bounds check. This c
In wpa_supplicant_8, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122529021
nvd
CVE-2019-2116P3HIGHCVSS 7.5v7.0v7.1.1+5 more2019-07-08
CVE-2019-2116 [HIGH] CWE-125 CVE-2019-2116: In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds
In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.
nvd
CVE-2019-2037P3HIGHCVSS 7.5v7.0v7.1.1+4 more2019-04-19
CVE-2019-2037 [HIGH] CWE-125 CVE-2019-2037: In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out-of-bound read due to an incorr
In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out-of-bound read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1
nvd
CVE-2023-20940P3HIGHCVSS 7.8v13.0vAndroid-132023-02-28
CVE-2023-20940 [HIGH] CWE-347 CVE-2023-20940: In the Android operating system, there is a possible way to replace a boot partition due to improper
In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-256237041
nvd
CVE-2020-0286P3HIGHCVSS 7.5v11.0vAndroid-112020-09-18
CVE-2020-0286 [HIGH] CWE-459 CVE-2020-0286: In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead
In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150214479
nvd
CVE-2020-0300P3HIGHCVSS 7.5v11.0vAndroid-112020-09-18
CVE-2020-0300 [HIGH] CWE-125 CVE-2020-0300: In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote
In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148736216
nvd
CVE-2020-0128P3HIGHCVSS 7.5v10.0vAndroid-102020-06-11
CVE-2020-0128 [HIGH] CWE-125 CVE-2020-0128: In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow
In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123940919
nvd
CVE-2020-0214P3HIGHCVSS 7.5v10.0vAndroid-102020-06-11
CVE-2020-0214 [HIGH] CWE-125 CVE-2020-0214: In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an inc
In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140292264
nvd
CVE-2019-9473P3HIGHCVSS 7.5v10.0vAndroid-102020-03-15
CVE-2019-9473 [HIGH] CWE-125 CVE-2019-9473: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-115363533
nvd
CVE-2019-9474P3HIGHCVSS 7.5v10.0vAndroid-102020-03-15
CVE-2019-9474 [HIGH] CWE-125 CVE-2019-9474: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-79996267
nvd
CVE-2019-9286P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9286 [HIGH] CWE-125 CVE-2019-9286: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111213909
nvd
CVE-2019-9326P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9326 [HIGH] CWE-125 CVE-2019-9326: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111215173
nvd
CVE-2019-9419P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9419 [HIGH] CWE-125 CVE-2019-9419: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111407544
nvd
CVE-2019-9413P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9413 [HIGH] CWE-125 CVE-2019-9413: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111935831
nvd