Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android
Total 8342 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2985 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 7.8 HIGH
In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
CVE-2022-2984 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 5.5 MEDIUM
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39117 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 5.5 MEDIUM
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVE-2022-39115 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 5.5 MEDIUM
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
CVE-2022-39114 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 5.5 MEDIUM
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
CVE-2022-39112 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 5.5 MEDIUM
In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.
CVE-2022-39111 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 7.8 HIGH
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
CVE-2022-39110 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-15 N/A 7.8 HIGH
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
CVE-2022-39128 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39127 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39126 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39125 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39124 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39123 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39122 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39121 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-14 N/A 5.5 MEDIUM
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2025-20665 2 Google, Mediatek 53 Android, Mt6580, Mt6761 and 50 more 2025-05-12 N/A 5.5 MEDIUM
In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09555228; Issue ID: MSV-2760.
CVE-2016-2427 2 Bouncycastle, Google 2 Bc-java, Android 2025-05-12 4.3 MEDIUM 5.5 MEDIUM
The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via a crafted application, aka internal bug 26234568. NOTE: The vendor disputes the existence of this potential issue in Android, stating "This CVE was raised in error: it referred to the authentication tag size in GCM, whose default according to ASN.1 encoding (12 bytes) can lead to vulnerabilities. After careful consideration, it was decided that the insecure default value of 12 bytes was a default only for the encoding and not default anywhere else in Android, and hence no vulnerability existed.
CVE-2024-20012 2 Google, Mediatek 51 Android, Mt6580, Mt6731 and 48 more 2025-05-09 N/A 6.7 MEDIUM
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.
CVE-2024-22012 1 Google 1 Android 2025-05-08 N/A 7.8 HIGH
there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.