Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Android Number Of NVD 6904 CRITICAL 484 HIGH 3022 MEDIUM 3149 LOW 241
URL https://www.android.com/
Explanation It is an operating system installed on smartphones provided by Google.
Since it is open source, many manufacturers use it in their smartphones, tablets, and wearable devices.

The support period differs for each development vendor.
After Google provides a security patch, it is up to the vendor to provide the patch to the target devices.
Tag
  • LGPL 2.1+
  • Mobile
  • Google
  • Apache License v2.0
  • GPL v2

Add Information URL
No Type Name URL
1 https://en.wikipedia.org/wiki/Android_version_history
2 https://source.android.com/setup/start/licenses
3 https://source.android.com/security/bulletin/
4 https://developer.android.com/
5 https://developer.android.com/about/versions/
6 https://android-developers.googleblog.com/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
691 Android 14 14.1 Nov. 6, 2024 Aug. 7, 2024 0 3 1 0
692 Android 13 13.4 Aug. 7, 2023 Aug. 15, 2022 15 317 812 67
693 Android 12 12.4 Oct. 17, 2022 Oct. 4, 2020 43 479 1193 106
694 Android 11 11 Sept. 8, 2020 Sept. 8, 2020 58 636 1364 107
695 Android 10 10 Sept. 3, 2019 Sept. 3, 2019 103 680 1055 110
696 Android 9 9 Aug. 6, 2018 Aug. 6, 2018 112 463 331 35
697 Android 8 8.1.0 Dec. 5, 2017 Aug. 21, 2017 144 529 318 25
698 Android 7 7.1.2 April 4, 2017 Aug. 22, 2016 116 627 380 20
699 Android 6 6.0.1 Dec. 7, 2015 Oct. 5, 2015 109 734 397 20
700 Android 5 5.1.1 April 21, 2015 Nov. 12, 2014 67 661 317 16
701 Android 4 4.4.4 June 19, 2014 Oct. 18, 2011 53 577 271 16
702 Android 3 3.2.6 Feb. 1, 2012 Feb. 22, 2011 25 420 174 10
703 Android 2 2.2.3 Nov. 21, 2011 Oct. 26, 2009 25 424 181 12
704 Android 1 1.6 Sept. 15, 2009 Sept. 23, 2008 150 1594 2337 209
705 Android 9.0 9.0 109 441 323 34
706 Android 7.2 7.2 16 61 79 9
707 Android 12.1 12.1 15 229 224 23
708 Android 12.0l 12.0l 0 28 68 9
709 Android 12.0 12.0 43 447 1159 104
710 Android 11.0 11.0 58 636 1364 107
711 Android 10.0 10.0 103 680 1055 110
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
691 5.5
-
MEDIUM
Local
In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This co… NVD-CWE-noinfo
CVE-2023-35675 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
692 7.8
-
HIGH
Local
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional executio… NVD-CWE-noinfo
CVE-2023-35674 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
693 8.8
-
HIGH
Adjacent
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution pr… CWE-190
 Integer Overflow or Wraparound
CVE-2023-35673 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
694 5.5
-
MEDIUM
Local
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode … NVD-CWE-noinfo
CVE-2023-35671 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
695 7.8
-
HIGH
Local
In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of p… CWE-22
Path Traversal
CVE-2023-35670 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
696 7.8
-
HIGH
Local
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of pri… CWE-502
 Deserialization of Untrusted Data
CVE-2023-35669 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
697 7.8
-
HIGH
Local
In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation… NVD-CWE-noinfo
CVE-2023-35667 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
698 7.8
-
HIGH
Local
In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed… CWE-416
 Use After Free
CVE-2023-35666 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
699 5.5
-
MEDIUM
Local
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution priv… CWE-125
Out-of-bounds Read
CVE-2023-35664 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
700 8.8
-
HIGH
Adjacent
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional executi… CWE-416
 Use After Free
CVE-2023-35658 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm