VendorsGoogleandroid11.0
Vulnerabilities

Google Android 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2103CVEs
CVE-2023-40128
In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-27 · Modified
7.8EPSS 0.001
CVE-2023-40116
In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-27 · Modified
7.8EPSS 0.001
CVE-2021-25428
Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.
Published 2021-07-08 · Modified
7.8EPSS 0.001
CVE-2023-35665
In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
7.8EPSS 0.001
CVE-2023-21093
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-228450832
Published 2023-04-19 · Modified
7.8EPSS 0.001
CVE-2023-21098
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-260567867
Published 2023-04-19 · Modified
7.8EPSS 0.001
CVE-2022-25815
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Published 2022-03-08 · Modified
7.8EPSS 0.001
CVE-2023-21129
In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background due to a BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-274759612
Published 2023-06-15 · Modified
7.8EPSS 0.001
CVE-2022-25814
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Published 2022-03-08 · Modified
7.8EPSS 0.001
CVE-2022-39119
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-21777
In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06713894; Issue ID: ALPS06713894.
Published 2022-07-06 · Modified
7.8EPSS 0.001
CVE-2023-20966
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242299736
Published 2023-03-24 · Modified
7.8EPSS 0.001
CVE-2023-21241
In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
7.8EPSS 0.001
CVE-2022-33695
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.
Published 2022-07-11 · Modified
7.8EPSS 0.001
CVE-2023-20906
In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher Target SDK with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-221040577
Published 2023-03-24 · Modified
7.8EPSS 0.001
CVE-2023-20931
In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242535997
Published 2023-03-24 · Modified
7.8EPSS 0.001
CVE-2023-42691
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42681
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42696
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-21229
In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
7.8EPSS 0.001
CVE-2023-35666
In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
7.8EPSS 0.001
CVE-2022-20349
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315522
Published 2022-08-09 · Modified
7.8EPSS 0.001
CVE-2023-42747
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42739
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42738
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42736
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42746
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42748
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42740
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42743
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-21081
In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-230492955
Published 2023-04-19 · Modified
7.8EPSS 0.001
CVE-2023-42745
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-21099
In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-243377226
Published 2023-04-19 · Modified
7.8EPSS 0.001
CVE-2021-39669
In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-196969991
Published 2022-02-11 · Modified
7.8EPSS 0.001
CVE-2023-20936
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-226927612
Published 2023-03-24 · Modified
7.8EPSS 0.001
CVE-2022-47361
In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
Published 2023-02-06 · Modified
7.8EPSS 0.001
CVE-2022-26429
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07025415; Issue ID: ALPS07025415.
Published 2022-08-01 · Modified
7.8EPSS 0.001
CVE-2022-32635
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ALPS07573237.
Published 2023-01-03 · Modified
7.8EPSS 0.001
CVE-2022-36849
Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
Published 2022-09-09 · Modified
7.8EPSS 0.001
CVE-2022-20611
In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242996180
Published 2022-12-13 · Modified
7.8EPSS 0.001
← Prev13 / 53Next →