VendorsGoogleandroid11.0
Vulnerabilities

Google Android 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2103CVEs
CVE-2023-38460
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-20950
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-195756028
Published 2023-04-19 · Modified
7.8EPSS 0.001
CVE-2023-38459
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38453
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38452
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38443
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38456
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38451
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38455
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38458
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38450
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38464
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-21121
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-205460459
Published 2023-06-15 · Modified
7.8EPSS 0.001
CVE-2023-21138
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-273260090
Published 2023-06-15 · Modified
7.8EPSS 0.001
CVE-2022-39883
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
Published 2022-11-09 · Modified
7.8EPSS 0.001
CVE-2023-40634
In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-10-08 · Modified
7.8EPSS 0.001
CVE-2023-40635
In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-10-08 · Modified
7.8EPSS 0.001
CVE-2022-28781
Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.
Published 2022-05-03 · Modified
7.7EPSS 0.001
CVE-2022-42756
In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.
Published 2022-12-06 · Modified
7.7EPSS 0.001
CVE-2022-22264
Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.
Published 2022-01-07 · Modified
7.7EPSS 0.001
CVE-2024-0040
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-16 · Analyzed
7.5EPSS 0.020
CVE-2021-0431
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a paired device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174149901
Published 2021-04-13 · Modified
7.5EPSS 0.017
CVE-2021-0435
In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174150451
Published 2021-04-13 · Modified
7.5EPSS 0.017
CVE-2020-0413
In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-158778659
Published 2020-10-14 · Modified
7.5EPSS 0.015
CVE-2020-0381
In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure in a highly constrained process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150159669
Published 2020-09-17 · Modified
7.5EPSS 0.015
CVE-2020-0463
In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-169342531
Published 2020-12-14 · Modified
7.5EPSS 0.015
CVE-2021-0522
In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-174182139
Published 2021-06-21 · Modified
7.5EPSS 0.014
CVE-2022-20224
In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220732646
Published 2022-07-13 · Modified
7.5EPSS 0.013
CVE-2020-27024
In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure triggered by a malformed Bluetooth packet, with no additional execution privileges needed. User interaction is not needed for exploitation. Bounds Sanitizer mitigates this in the default configuration.Product: AndroidVersions: Android-11Android ID: A-162327732
Published 2020-12-15 · Modified
7.5EPSS 0.010
CVE-2021-0630
In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05551397; Issue ID: ALPS05551397.
Published 2021-10-25 · Modified
7.5EPSS 0.009
CVE-2021-0631
In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05551435; Issue ID: ALPS05551435.
Published 2021-10-25 · Modified
7.5EPSS 0.009
CVE-2021-0341
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-171980069
Published 2021-02-10 · Modified
7.5EPSS 0.009
CVE-2020-0286
In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150214479
Published 2020-09-18 · Modified
7.5EPSS 0.008
CVE-2020-0300
In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148736216
Published 2020-09-18 · Modified
7.5EPSS 0.008
CVE-2021-0517
In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179053823
Published 2021-06-21 · Modified
7.5EPSS 0.008
CVE-2021-0555
In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179161711
Published 2021-06-22 · Modified
7.5EPSS 0.008
CVE-2020-0460
In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-163413737
Published 2020-12-14 · Modified
7.5EPSS 0.008
CVE-2021-39809
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205837191
Published 2022-04-12 · Modified
7.5EPSS 0.008
CVE-2023-21144
In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252766417
Published 2023-06-15 · Modified
7.5EPSS 0.007
CVE-2022-20410
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-205570663
Published 2022-10-11 · Modified
7.5EPSS 0.007
← Prev15 / 53Next →