VendorsGoogleandroid11.0
Vulnerabilities

Google Android 11.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2103CVEs
CVE-2023-42728
In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42720
In video service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42723
In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-33899
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33887
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2022-21763
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044708.
Published 2022-07-06 · Modified
5.5EPSS 0.001
CVE-2022-21764
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044717.
Published 2022-07-06 · Modified
5.5EPSS 0.001
CVE-2023-42721
In flv extractor, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-33895
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33888
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-33885
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2022-28785
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
Published 2022-05-03 · Modified
5.5EPSS 0.001
CVE-2022-28786
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
Published 2022-05-03 · Modified
5.5EPSS 0.001
CVE-2022-28787
Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
Published 2022-05-03 · Modified
5.5EPSS 0.001
CVE-2022-28788
Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.
Published 2022-05-03 · Modified
5.5EPSS 0.001
CVE-2022-20129
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-217934478
Published 2022-06-15 · Modified
5.5EPSS 0.001
CVE-2022-20143
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220735360
Published 2022-06-15 · Modified
5.5EPSS 0.001
CVE-2022-20225
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213457638
Published 2022-07-13 · Modified
5.5EPSS 0.001
CVE-2022-21748
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06511030; Issue ID: ALPS06511030.
Published 2022-06-06 · Modified
5.5EPSS 0.001
CVE-2022-21749
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511058; Issue ID: ALPS06511058.
Published 2022-06-06 · Modified
5.5EPSS 0.001
CVE-2023-21103
In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-259064622
Published 2023-05-15 · Modified
5.5EPSS 0.001
CVE-2022-38690
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
Published 2022-10-14 · Modified
5.5EPSS 0.001
CVE-2021-25460
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
Published 2021-09-09 · Modified
5.5EPSS 0.001
CVE-2022-20112
In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-206987762
Published 2022-05-10 · Modified
5.5EPSS 0.001
CVE-2022-28780
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.
Published 2022-05-03 · Modified
5.5EPSS 0.001
CVE-2021-0934
In findAllDeAccounts of AccountsDb.java, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-169762606
Published 2022-12-13 · Modified
5.5EPSS 0.001
CVE-2023-42712
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2022-39131
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
Published 2022-12-06 · Modified
5.5EPSS 0.001
CVE-2022-42775
In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of service in kernel.
Published 2022-12-06 · Modified
5.5EPSS 0.001
CVE-2023-42711
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42710
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42708
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42709
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42707
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42733
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42732
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42705
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42704
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42703
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
CVE-2023-42702
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-12-04 · Modified
5.5EPSS 0.001
← Prev38 / 53Next →