VendorsGoogleandroid10.0
Vulnerabilities

Google Android 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1849CVEs
CVE-2019-2149
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113262406
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2150
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117935831
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2151
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117495174
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2152
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118145923
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2153
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112611181
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2154
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117610057
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2155
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117655547
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2156
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112552816
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2079
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115509210
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2157
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112611363
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2019-2158
In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118766492
Published 2019-09-27 · Modified
6.5EPSS 0.006
CVE-2021-0969
In getTitle of AccessPoint.java, there is a possible unhandled exception due to a missing null check. This could lead to remote denial of service if a proximal Wi-Fi AP provides invalid information with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-199922685
Published 2021-12-15 · Modified
6.5EPSS 0.006
CVE-2019-9380
In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permission settings with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-123700098
Published 2019-09-27 · Modified
6.5EPSS 0.005
CVE-2020-10844
An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There is an out-of-bounds read vulnerability in media.audio_policy. The Samsung ID is SVE-2019-16333 (February 2020).
Published 2020-03-24 · Modified
6.5EPSS 0.004
CVE-2019-2227
In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-140768453
Published 2019-12-06 · Modified
6.5EPSS 0.003
CVE-2020-0196
In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144066833
Published 2020-06-11 · Modified
6.5EPSS 0.003
CVE-2021-0632
In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker under certain build conditions with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05560246; Issue ID: ALPS05551383.
Published 2021-10-25 · Modified
6.5EPSS 0.003
CVE-2022-20023
In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198608; Issue ID: ALPS06198608.
Published 2022-01-04 · Modified
6.5EPSS 0.003
CVE-2022-20022
In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from a host with the same BD address as the currently connected BT host. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198578; Issue ID: ALPS06198578.
Published 2022-01-04 · Modified
6.5EPSS 0.003
CVE-2022-20021
In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple LMP_host_connection_req. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198513; Issue ID: ALPS06198513.
Published 2022-01-04 · Modified
6.5EPSS 0.003
CVE-2022-20221
In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205571133
Published 2022-07-13 · Modified
6.5EPSS 0.003
CVE-2021-25483
Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.
Published 2021-10-06 · Modified
6.5EPSS 0.002
CVE-2021-25514
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.
Published 2021-12-08 · Modified
6.5EPSS 0.002
CVE-2021-25427
SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information
Published 2021-07-08 · Modified
6.5EPSS 0.002
CVE-2021-25450
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.
Published 2021-09-09 · Modified
6.5EPSS 0.002
CVE-2022-20468
In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-228450451
Published 2022-12-13 · Modified
6.5EPSS 0.001
CVE-2021-25416
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
Published 2021-06-11 · Modified
6.5EPSS 0.001
CVE-2020-0305
In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153467744
Published 2020-07-17 · Modified
6.4EPSS 0.002
CVE-2020-10845
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a race condition leading to a use-after-free in MTP. The Samsung ID is SVE-2019-16520 (February 2020).
Published 2020-03-24 · Modified
6.4EPSS 0.001
CVE-2022-47322
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-47365
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-47366
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-44448
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-42783
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-38686
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-47324
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-47329
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-47325
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-47326
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
Published 2023-02-06 · Modified
6.4EPSS 0.001
CVE-2022-47328
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
Published 2023-02-06 · Modified
6.4EPSS 0.001
← Prev27 / 47Next →