Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android
Total 8334 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-42651 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 5.5 MEDIUM
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42652 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 5.5 MEDIUM
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-40139 1 Google 1 Android 2023-11-08 N/A 5.5 MEDIUM
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2022-48457 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 5.5 MEDIUM
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVE-2022-48455 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 5.5 MEDIUM
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVE-2022-48454 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 5.5 MEDIUM
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVE-2022-48456 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 4.4 MEDIUM
In camera driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local denial of service with System execution privileges needed
CVE-2022-48460 2 Google, Unisoc 13 Android, Sc7731e, Sc9832e and 10 more 2023-11-08 N/A 5.5 MEDIUM
In setting service, there is a possible undefined behavior due to incorrect error handling. This could lead to local denial of service with no additional execution privileges needed
CVE-2022-48459 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 5.5 MEDIUM
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVE-2022-48461 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 4.4 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVE-2022-48458 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-11-08 N/A 5.5 MEDIUM
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-30730 2 Google, Samsung 2 Android, Camera 2023-11-07 N/A 5.5 MEDIUM
Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12.1.03.10 in Android 12, and 13.0.01.43, 13.1.00.83 in Android 13 allows local attacker to access specific file.
CVE-2023-30678 2 Google, Samsung 2 Android, Calendar 2023-11-07 N/A 5.5 MEDIUM
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.
CVE-2023-21419 1 Google 1 Android 2023-11-07 N/A 7.5 HIGH
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.
CVE-2022-2611 2 Fedoraproject, Google 3 Fedora, Android, Chrome 2023-11-07 N/A 4.3 MEDIUM
Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2022-2623 2 Fedoraproject, Google 3 Fedora, Android, Chrome 2023-11-07 N/A 8.8 HIGH
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
CVE-2022-2479 1 Google 2 Android, Chrome 2023-11-07 N/A 4.3 MEDIUM
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page.
CVE-2021-38020 3 Debian, Fedoraproject, Google 4 Debian Linux, Fedora, Android and 1 more 2023-11-07 4.3 MEDIUM 4.3 MEDIUM
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2021-39635 1 Google 1 Android 2023-11-07 9.4 HIGH 9.1 CRITICAL
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634
CVE-2021-37966 3 Debian, Fedoraproject, Google 4 Debian Linux, Fedora, Android and 1 more 2023-11-07 4.3 MEDIUM 4.3 MEDIUM
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.