cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 94 of 339
CVE-2019-9387P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9387 [HIGH] CWE-125 CVE-2019-9387: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117569833
nvd
CVE-2019-9343P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9343 [HIGH] CWE-125 CVE-2019-9343: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112050983
nvd
CVE-2019-9330P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9330 [HIGH] CWE-125 CVE-2019-9330: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214739
nvd
CVE-2019-9331P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9331 [HIGH] CWE-125 CVE-2019-9331: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112272279
nvd
CVE-2019-9241P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9241 [HIGH] CWE-125 CVE-2019-9241: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121036603
nvd
CVE-2019-9355P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9355 [HIGH] CWE-125 CVE-2019-9355: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115903122
nvd
CVE-2019-9422P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9422 [HIGH] CWE-125 CVE-2019-9422: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214766
nvd
CVE-2019-9388P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9388 [HIGH] CWE-125 CVE-2019-9388: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117567437
nvd
CVE-2019-9341P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9341 [HIGH] CWE-125 CVE-2019-9341: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214770
nvd
CVE-2019-9342P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9342 [HIGH] CWE-125 CVE-2019-9342: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214470
nvd
CVE-2019-9327P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9327 [HIGH] CWE-125 CVE-2019-9327: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112050583
nvd
CVE-2019-9250P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9250 [HIGH] CWE-125 CVE-2019-9250: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120276962
nvd
CVE-2021-1022P3HIGHCVSS 7.5v12.0vAndroid-122021-12-15
CVE-2021-1022 [HIGH] CWE-476 CVE-2021-1022: In btif_in_hf_client_generic_evt of btif_hf_client.cc, there is a possible Bluetooth service crash d In btif_in_hf_client_generic_evt of btif_hf_client.cc, there is a possible Bluetooth service crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-180420059
nvd
CVE-2023-21144P3HIGHCVSS 7.5v11.0v12.0+3 more2023-06-15
CVE-2023-21144 [HIGH] CWE-770 CVE-2023-21144: In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or servi In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android
nvd
CVE-2019-2211P3HIGHCVSS 7.5v8.0v8.1+3 more2019-11-13
CVE-2019-2211 [HIGH] CWE-89 CVE-2019-2211: In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269669
nvd
CVE-2021-25426P3HIGHCVSS 7.5v9.0v10.0+1 more2021-07-08
CVE-2021-25426 [HIGH] CWE-200 CVE-2021-25426: Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR Jul Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 allows untrusted applications to access Message files.
nvd
CVE-2016-2419P3CRITICALCVSS 9.8v6.0v6.0.12016-04-18
CVE-2016-2419 [CRITICAL] CWE-264 CVE-2016-2419: media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certai media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem
nvd
CVE-2023-40632P3HIGHCVSS 7.5v13.02023-10-08
CVE-2023-40632 [HIGH] CWE-416 CVE-2023-40632: In jpg driver, there is a possible use after free due to a logic error. This could lead to remote in In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2021-25417P3HIGHCVSS 7.5v9.0v10.02021-06-11
CVE-2021-25417 [HIGH] CWE-285 CVE-2021-25417: Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage. Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.
nvd
CVE-2017-0822P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2017-10-04
CVE-2017-0822 [CRITICAL] CVE-2017-0822: An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: An elevation of privilege vulnerability in the Android system (camera). Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63787722.
nvd
Google Android vulnerabilities | cvebase