VendorsGoogleandroid10.0
Vulnerabilities

Google Android 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1849CVEs
CVE-2020-0079
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144506242
Published 2020-04-17 · Modified
7.8EPSS 0.002
CVE-2020-0102
In GattServer::SendResponse of gatt_server.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143231677
Published 2020-05-14 · Modified
7.8EPSS 0.002
CVE-2020-0129
In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123292010
Published 2020-06-11 · Modified
7.8EPSS 0.002
CVE-2020-0150
In rw_t3t_message_set_block_list of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142280329
Published 2020-06-11 · Modified
7.8EPSS 0.002
CVE-2019-9350
In Keymaster, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-129562815
Published 2019-09-27 · Modified
7.8EPSS 0.002
CVE-2022-39107
In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-39108
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-38698
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2020-0120
In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-149995442
Published 2020-07-17 · Modified
7.8EPSS 0.002
CVE-2022-39109
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-39110
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-39111
In Music service, there is a missing permission check. This could lead to elevation of privilege in Music service with no additional execution privileges needed.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-39080
In messaging service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-39101
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2022-20124
In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre-loaded applications for other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-170646036
Published 2022-06-15 · Modified
7.8EPSS 0.002
CVE-2022-39100
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2022-39096
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2022-39095
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2022-39094
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2022-39099
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2022-39102
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2020-10838
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and arbitrary code execution. The Samsung ID is SVE-2019-16132 (February 2020).
Published 2020-03-24 · Modified
7.8EPSS 0.002
CVE-2019-2218
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installing malicious packages with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141169173
Published 2019-12-06 · Modified
7.8EPSS 0.002
CVE-2020-0243
In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-8.0 Android-8.1Android ID: A-151644303
Published 2020-08-11 · Modified
7.8EPSS 0.002
CVE-2022-39098
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2022-39097
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
Published 2022-12-06 · Modified
7.8EPSS 0.002
CVE-2021-39663
In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-200682135
Published 2022-02-11 · Modified
7.8EPSS 0.002
CVE-2021-0708
In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-183262161
Published 2021-10-22 · Modified
7.8EPSS 0.002
CVE-2020-0208
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145207098
Published 2020-06-11 · Modified
7.8EPSS 0.001
CVE-2021-39674
In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442
Published 2022-02-11 · Modified
7.8EPSS 0.001
CVE-2019-9295
In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-36885811
Published 2019-09-27 · Modified
7.8EPSS 0.001
CVE-2022-20025
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126832; Issue ID: ALPS06126832.
Published 2022-02-09 · Modified
7.8EPSS 0.001
CVE-2022-20044
In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID: ALPS06126814.
Published 2022-02-09 · Modified
7.8EPSS 0.001
CVE-2022-20045
In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID: ALPS06126820.
Published 2022-02-09 · Modified
7.8EPSS 0.001
CVE-2022-20028
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198663; Issue ID: ALPS06198663.
Published 2022-02-09 · Modified
7.8EPSS 0.001
CVE-2022-20026
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126827; Issue ID: ALPS06126827.
Published 2022-02-09 · Modified
7.8EPSS 0.001
CVE-2022-20027
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126826; Issue ID: ALPS06126826.
Published 2022-02-09 · Modified
7.8EPSS 0.001
CVE-2019-9263
In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73136824
Published 2019-09-27 · Modified
7.8EPSS 0.001
CVE-2018-9425
In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73884967
Published 2019-09-27 · Modified
7.8EPSS 0.001
CVE-2020-0084
In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143339775
Published 2020-03-10 · Modified
7.8EPSS 0.001
← Prev11 / 47Next →