Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-0709 | Low | 0.21 | 3.3 | 0.00 | Jul 6, 2017 | A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048. | ||
| CVE-2015-9032 | Low | 0.21 | 3.3 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications. | ||
| CVE-2015-9031 | Low | 0.21 | 3.3 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP. | ||
| CVE-2016-6770 | Low | 0.21 | 3.3 | 0.00 | Jan 12, 2017 | An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android.… | ||
| CVE-2016-3763 | Low | 0.21 | 3.3 | 0.01 | Jul 11, 2016 | net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to… | ||
| CVE-2016-3759 | Low | 0.21 | 3.3 | 0.00 | Jul 11, 2016 | The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080. | ||
| CVE-2023-21262 | Low | 0.20 | 3.1 | 0.00 | Jul 13, 2023 | In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation. | ||
| CVE-2021-25454 | Low | 0.20 | 3.1 | 0.00 | Sep 9, 2021 | OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file. | ||
| CVE-2015-6641 | Low | 0.20 | 3.1 | 0.00 | Jan 6, 2016 | Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427. | ||
| CVE-2026-0121 | Low | 0.19 | 2.9 | 0.00 | Mar 10, 2026 | In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2022-27834 | Low | 0.19 | 2.9 | 0.00 | Apr 11, 2022 | Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions. | ||
| CVE-2022-27831 | Low | 0.19 | 2.9 | 0.00 | Apr 11, 2022 | Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory. | ||
| CVE-2016-0823 | Med | 0.19 | 4.0 | 0.00 | Mar 12, 2016 | The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721. | ||
| CVE-2022-20327 | Low | 0.18 | 2.8 | 0.00 | Aug 12, 2022 | In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product:… | ||
| CVE-2021-25336 | Low | 0.18 | 2.8 | 0.00 | Mar 4, 2021 | Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent. | ||
| CVE-2022-20529 | Low | 0.16 | 2.4 | 0.00 | Dec 16, 2022 | In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20245 | Low | 0.16 | 2.4 | 0.00 | Aug 11, 2022 | In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:… | ||
| CVE-2022-33720 | Low | 0.16 | 2.4 | 0.00 | Aug 5, 2022 | Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut. | ||
| CVE-2022-30721 | Low | 0.16 | 2.5 | 0.00 | Jun 7, 2022 | Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash. | ||
| CVE-2022-30720 | Low | 0.16 | 2.5 | 0.00 | Jun 7, 2022 | Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash. |
- risk 0.21cvss 3.3epss 0.00
A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.
- risk 0.21cvss 3.3epss 0.00
In all Android releases from CAF using the Linux kernel, a DRM key was exposed to QTEE applications.
- risk 0.21cvss 3.3epss 0.00
In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.
- risk 0.21cvss 3.3epss 0.00
An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android.…
- risk 0.21cvss 3.3epss 0.01
net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to…
- risk 0.21cvss 3.3epss 0.00
The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.
- risk 0.20cvss 3.1epss 0.00
In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.
- risk 0.20cvss 3.1epss 0.00
OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.
- risk 0.20cvss 3.1epss 0.00
Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.
- risk 0.19cvss 2.9epss 0.00
In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.19cvss 2.9epss 0.00
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.
- risk 0.19cvss 2.9epss 0.00
Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.
- risk 0.19cvss 4.0epss 0.00
The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.
- risk 0.18cvss 2.8epss 0.00
In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product:…
- risk 0.18cvss 2.8epss 0.00
Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.
- risk 0.16cvss 2.4epss 0.00
In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User interaction is not needed for…
- risk 0.16cvss 2.4epss 0.00
In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…
- risk 0.16cvss 2.4epss 0.00
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.
- risk 0.16cvss 2.5epss 0.00
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
- risk 0.16cvss 2.5epss 0.00
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.
Page 414 of 426