Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39658 | Cri | 0.64 | 9.8 | 0.01 | Feb 11, 2022 | ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system… | ||
| CVE-2021-39616 | Cri | 0.64 | 9.8 | 0.01 | Feb 11, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438 | ||
| CVE-2021-39623 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2022 | In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-1049 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2022 | Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722 | ||
| CVE-2021-39655 | Cri | 0.64 | 9.8 | 0.00 | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A | ||
| CVE-2021-39645 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A | ||
| CVE-2021-39644 | Cri | 0.64 | 9.8 | 0.00 | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A | ||
| CVE-2021-39641 | Cri | 0.64 | 9.8 | 0.00 | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A | ||
| CVE-2021-0956 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2021 | In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-0889 | Cri | 0.64 | 9.8 | 0.02 | Dec 15, 2021 | In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10… | ||
| CVE-2021-0869 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2021 | In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android… | ||
| CVE-2021-0515 | Cri | 0.64 | 9.8 | 0.01 | Jul 14, 2021 | In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-0516 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2021 | In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-0324 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2021 | Product: AndroidVersions: Android SoCAndroid ID: A-175402462 | ||
| CVE-2021-0474 | Cri | 0.64 | 9.8 | 0.03 | Jun 11, 2021 | In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11… | ||
| CVE-2021-0430 | Cri | 0.64 | 9.8 | 0.03 | Apr 13, 2021 | In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-0397 | Cri | 0.64 | 9.8 | 0.06 | Mar 10, 2021 | In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11… | ||
| CVE-2021-0396 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2021 | In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed.… | ||
| CVE-2021-26689 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2021 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021). | ||
| CVE-2021-26688 | Cri | 0.64 | 9.8 | 0.00 | Feb 4, 2021 | An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021). |
- risk 0.64cvss 9.8epss 0.01
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system…
- risk 0.64cvss 9.8epss 0.01
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438
- risk 0.64cvss 9.8epss 0.02
In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.01
Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A
- risk 0.64cvss 9.8epss 0.00
Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A
- risk 0.64cvss 9.8epss 0.01
In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.02
In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…
- risk 0.64cvss 9.8epss 0.01
In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…
- risk 0.64cvss 9.8epss 0.01
In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.02
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.01
Product: AndroidVersions: Android SoCAndroid ID: A-175402462
- risk 0.64cvss 9.8epss 0.03
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11…
- risk 0.64cvss 9.8epss 0.03
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.8epss 0.06
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11…
- risk 0.64cvss 9.8epss 0.02
In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed.…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).
- risk 0.64cvss 9.8epss 0.00
An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).
Page 9 of 426