Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20765 | Med | 0.31 | 4.7 | 0.00 | Dec 2, 2025 | In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833. | ||
| CVE-2024-32904 | Med | 0.31 | 4.7 | 0.00 | Jun 13, 2024 | In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation. | ||
| CVE-2024-32898 | Med | 0.31 | 4.7 | 0.00 | Jun 13, 2024 | In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation. | ||
| CVE-2024-29778 | Med | 0.31 | 4.7 | 0.00 | Jun 13, 2024 | In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for… | ||
| CVE-2023-21095 | Med | 0.31 | 4.7 | 0.00 | Jun 15, 2023 | In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21031 | Med | 0.31 | 4.7 | 0.00 | Mar 24, 2023 | In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-47331 | Med | 0.31 | 4.7 | 0.00 | Feb 12, 2023 | In wlan driver, there is a race condition. This could lead to local denial of service in wlan services. | ||
| CVE-2022-20214 | Med | 0.31 | 4.7 | 0.00 | Jan 26, 2023 | In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID:… | ||
| CVE-2022-42771 | Med | 0.31 | 4.7 | 0.00 | Dec 6, 2022 | In wlan driver, there is a race condition, This could lead to local denial of service in wlan services. | ||
| CVE-2022-42770 | Med | 0.31 | 4.7 | 0.00 | Dec 6, 2022 | In wlan driver, there is a race condition, This could lead to local denial of service in wlan services. | ||
| CVE-2022-39134 | Med | 0.31 | 4.7 | 0.00 | Dec 6, 2022 | In audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel. | ||
| CVE-2022-33727 | Med | 0.31 | 4.8 | 0.00 | Aug 5, 2022 | A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack. | ||
| CVE-2022-33723 | Med | 0.31 | 4.8 | 0.00 | Aug 5, 2022 | A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack. | ||
| CVE-2022-20097 | Med | 0.31 | 4.7 | 0.00 | May 3, 2022 | In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06383944. | ||
| CVE-2021-0443 | Med | 0.31 | 4.7 | 0.00 | Apr 13, 2021 | In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition. This could lead to local information disclosure across user profiles with no additional execution privileges needed. User interaction is… | ||
| CVE-2021-0320 | Med | 0.31 | 4.7 | 0.00 | Jan 11, 2021 | In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition. This could lead to local information disclosure with no additional execution privileges needed.… | ||
| CVE-2020-0373 | Med | 0.31 | 4.7 | 0.00 | Sep 17, 2020 | In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android… | ||
| CVE-2015-9546 | Med | 0.31 | 4.8 | 0.00 | Apr 10, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences… | ||
| CVE-2020-0008 | Med | 0.31 | 4.7 | 0.00 | Jan 8, 2020 | In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.… | ||
| CVE-2019-2219 | Med | 0.31 | 4.7 | 0.00 | Dec 6, 2019 | In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges… |
- risk 0.31cvss 4.7epss 0.00
In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833.
- risk 0.31cvss 4.7epss 0.00
In ProtocolVsimOperationAdapter() of protocolvsimadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
- risk 0.31cvss 4.7epss 0.00
In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
- risk 0.31cvss 4.7epss 0.00
In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for…
- risk 0.31cvss 4.7epss 0.00
In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.31cvss 4.7epss 0.00
In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.31cvss 4.7epss 0.00
In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.
- risk 0.31cvss 4.7epss 0.00
In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID:…
- risk 0.31cvss 4.7epss 0.00
In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.
- risk 0.31cvss 4.7epss 0.00
In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.
- risk 0.31cvss 4.7epss 0.00
In audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel.
- risk 0.31cvss 4.8epss 0.00
A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- risk 0.31cvss 4.8epss 0.00
A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- risk 0.31cvss 4.7epss 0.00
In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06383944.
- risk 0.31cvss 4.7epss 0.00
In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition. This could lead to local information disclosure across user profiles with no additional execution privileges needed. User interaction is…
- risk 0.31cvss 4.7epss 0.00
In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen requirements for keyguard bound keys due to a race condition. This could lead to local information disclosure with no additional execution privileges needed.…
- risk 0.31cvss 4.7epss 0.00
In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android…
- risk 0.31cvss 4.8epss 0.00
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences…
- risk 0.31cvss 4.7epss 0.00
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.…
- risk 0.31cvss 4.7epss 0.00
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges…
Page 370 of 426