VendorsGoogleandroid11.0
Vulnerabilities

Google Android 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2103CVEs
CVE-2021-0554
In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158482162
Published 2021-06-22 · Modified
5.5EPSS 0.001
CVE-2023-21243
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2021-0641
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185235454
Published 2021-08-17 · Modified
5.5EPSS 0.001
CVE-2021-0643
In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183612370
Published 2021-10-22 · Modified
5.5EPSS 0.001
CVE-2022-25819
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.
Published 2022-03-08 · Modified
5.5EPSS 0.001
CVE-2021-30161
An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection mechanism after an incoming call has been terminated. The LG ID is LVE-SMP-210002 (April 2021).
Published 2021-04-06 · Modified
5.5EPSS 0.001
CVE-2024-0020
In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-16 · Modified
5.5EPSS 0.001
CVE-2023-21136
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-246542285
Published 2023-06-15 · Modified
5.5EPSS 0.001
CVE-2021-0706
In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-193444889
Published 2021-10-22 · Modified
5.5EPSS 0.001
CVE-2021-25453
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
Published 2021-09-09 · Modified
5.5EPSS 0.001
CVE-2023-21252
In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-06 · Modified
5.5EPSS 0.001
CVE-2022-33685
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.
Published 2022-07-11 · Modified
5.5EPSS 0.001
CVE-2023-35679
In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2023-09-11 · Modified
5.5EPSS 0.001
CVE-2024-0017
In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2024-02-16 · Analyzed
5.5EPSS 0.001
CVE-2022-20051
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219127; Issue ID: ALPS06219127.
Published 2022-03-09 · Modified
5.5EPSS 0.001
CVE-2022-22291
Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.
Published 2022-02-11 · Modified
5.5EPSS 0.001
CVE-2023-21105
In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261036568
Published 2023-06-15 · Modified
5.5EPSS 0.001
CVE-2023-21291
In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-06 · Modified
5.5EPSS 0.001
CVE-2022-20393
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-233735886
Published 2022-09-13 · Modified
5.5EPSS 0.001
CVE-2022-33715
Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.
Published 2022-08-05 · Modified
5.5EPSS 0.001
CVE-2021-25392
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.
Published 2021-06-11 · Modified
5.5EPSS 0.001
CVE-2022-20467
In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-225880741
Published 2023-03-24 · Modified
5.5EPSS 0.001
CVE-2023-21268
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.001
CVE-2023-42718
In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42715
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2022-20355
In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-219498290
Published 2022-08-09 · Modified
5.5EPSS 0.001
CVE-2022-20353
In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221041256
Published 2022-08-09 · Modified
5.5EPSS 0.001
CVE-2023-33885
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33884
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33883
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2022-30758
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.
Published 2022-07-11 · Modified
5.5EPSS 0.001
CVE-2023-33895
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33900
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33899
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2022-36854
Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.
Published 2022-09-09 · Modified
5.5EPSS 0.001
CVE-2023-33889
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-35677
In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
5.5EPSS 0.001
CVE-2023-33892
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33893
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33891
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
← Prev37 / 53Next →