Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Android Number Of NVD 6839 CRITICAL 484 HIGH 2987 MEDIUM 3124 LOW 236
URL https://www.android.com/
Explanation It is an operating system installed on smartphones provided by Google.
Since it is open source, many manufacturers use it in their smartphones, tablets, and wearable devices.

The support period differs for each development vendor.
After Google provides a security patch, it is up to the vendor to provide the patch to the target devices.
Tag
  • Google
  • Apache License v2.0
  • GPL v2
  • LGPL 2.1+
  • Mobile

Add Information URL
No Type Name URL
1 https://en.wikipedia.org/wiki/Android_version_history
2 https://source.android.com/setup/start/licenses
3 https://source.android.com/security/bulletin/
4 https://developer.android.com/
5 https://developer.android.com/about/versions/
6 https://android-developers.googleblog.com/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
621 Android 14 14.1 Nov. 6, 2024 Aug. 7, 2024 0 3 1 0
622 Android 13 13.4 Aug. 7, 2023 Aug. 15, 2022 15 311 812 67
623 Android 12 12.4 Oct. 17, 2022 Oct. 4, 2020 43 479 1193 106
624 Android 11 11 Sept. 8, 2020 Sept. 8, 2020 58 636 1364 107
625 Android 10 10 Sept. 3, 2019 Sept. 3, 2019 103 680 1055 110
626 Android 9 9 Aug. 6, 2018 Aug. 6, 2018 112 463 331 35
627 Android 8 8.1.0 Dec. 5, 2017 Aug. 21, 2017 144 529 318 25
628 Android 7 7.1.2 April 4, 2017 Aug. 22, 2016 116 627 380 20
629 Android 6 6.0.1 Dec. 7, 2015 Oct. 5, 2015 109 734 397 20
630 Android 5 5.1.1 April 21, 2015 Nov. 12, 2014 67 661 317 16
631 Android 4 4.4.4 June 19, 2014 Oct. 18, 2011 53 577 271 16
632 Android 3 3.2.6 Feb. 1, 2012 Feb. 22, 2011 25 420 174 10
633 Android 2 2.2.3 Nov. 21, 2011 Oct. 26, 2009 25 424 181 12
634 Android 1 1.6 Sept. 15, 2009 Sept. 23, 2008 150 1559 2312 204
635 Android 9.0 9.0 109 441 323 34
636 Android 7.2 7.2 16 61 79 9
637 Android 12.1 12.1 15 229 224 23
638 Android 12.0l 12.0l 0 28 68 9
639 Android 12.0 12.0 43 447 1159 104
640 Android 11.0 11.0 58 636 1364 107
641 Android 10.0 10.0 103 680 1055 110
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
621 9.8
-
CRITICAL
Network
In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges n… CWE-787
CWE-190
 Out-of-bounds Write
 Integer Overflow or Wraparound
CVE-2023-35681 cpe:2.3:o:google:android:13.0:* 2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
622 5.5
-
MEDIUM
Local
In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privi… NVD-CWE-Other
CVE-2023-35680 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
623 5.5
-
MEDIUM
Local
In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed.… CWE-125
Out-of-bounds Read
CVE-2023-35679 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
624 5.5
-
MEDIUM
Local
In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous l… NVD-CWE-noinfo
CVE-2023-35677 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
625 7.8
-
HIGH
Local
In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of pri… NVD-CWE-noinfo
CVE-2023-35676 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
626 5.5
-
MEDIUM
Local
In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This co… NVD-CWE-noinfo
CVE-2023-35675 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
627 7.8
-
HIGH
Local
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional executio… NVD-CWE-noinfo
CVE-2023-35674 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
628 8.8
-
HIGH
Adjacent
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution pr… CWE-190
 Integer Overflow or Wraparound
CVE-2023-35673 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
629 5.5
-
MEDIUM
Local
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode … NVD-CWE-noinfo
CVE-2023-35671 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm
630 7.8
-
HIGH
Local
In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of p… CWE-22
Path Traversal
CVE-2023-35670 cpe:2.3:o:google:android:13.0:*
cpe:2.3:o:google:android:12.1:*
cpe:2.3:o:google:android:12.0:*
cpe:2.3:o:goog…
2024-11-21 17:08
2023-09-12
Show GitHub Exploit DB Packet Storm