Platform Frameworks Av vulnerabilities
82 known vulnerabilities affecting platform/frameworks_av.
Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN82
Vulnerabilities
Page 2 of 5
CVE-2024-34736P3UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 12:0, < 12:2024-08-01+3 more2024-08-01
CVE-2024-34736 CVE-2024-34736: In setupVideoEncoder of StagefrightRecorder
In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabled. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0519P3UNKNOWN≥ 10:0, < 10:2021-08-012021-08-01
CVE-2021-0519 CVE-2021-0519: In BITSTREAM_FLUSH of ih264e_bitstream
In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40096P3UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 11:0, < 11:2023-12-01+4 more2023-12-01
CVE-2023-40096 CVE-2023-40096: In OpRecordAudioMonitor::onFirstRef of AudioRecordClient
In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the background due to a missing flag. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20933P3UNKNOWN≥ 10:0, < 10:2023-02-01≥ 11:0, < 11:2023-02-01+3 more2023-02-01
CVE-2023-20933 CVE-2023-20933: In several functions of MediaCodec
In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35687P3UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35687 CVE-2023-35687: In MtpPropertyValue of MtpProperty
In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20934P3UNKNOWN≥ 12:0, < 12:2023-02-01≥ 12L:0, < 12L:2023-02-01+1 more2023-02-01
CVE-2023-20934 CVE-2023-20934: In resolveAttributionSource of ServiceUtilities
In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0483P3UNKNOWN≥ 12-next:0, < 12-next:2021-10-01≥ 10:0, < 10:2021-10-01+2 more2021-10-01
CVE-2021-0483 CVE-2021-0483: In multiple methods of AAudioService, there is a possible use-after-free due to a race condition
In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40107P3UNKNOWN≥ 14-next:0, < 14-next:2023-11-01≥ 12:0, < 12:2023-11-01+3 more2023-11-01
CVE-2023-40107 CVE-2023-40107: In ARTPWriter of ARTPWriter
In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0242P3UNKNOWN≥ 8.0:0, < 8.0:2020-08-01≥ 8.1:0, < 8.1:2020-08-01+2 more2020-08-01
CVE-2020-0242 CVE-2020-0242: In reset of NuPlayerDriver
In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0510P3UNKNOWN≥ 9:0, < 9:2021-06-01≥ 10:0, < 10:2021-06-01+1 more2021-06-01
CVE-2021-0510 CVE-2021-0510: In decrypt_1_2 of CryptoPlugin
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0243P3UNKNOWN≥ 8.0:0, < 8.0:2020-08-01≥ 8.1:0, < 8.1:2020-08-01+2 more2020-08-01
CVE-2020-0243 CVE-2020-0243: In clearPropValue of MediaAnalyticsItem
In clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20542P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2022-20542 CVE-2022-20542: In parseParamsBlob of types
In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40110P3UNKNOWN≥ 11:0, < 11:2023-11-01≥ 12:0, < 12:2023-11-01+3 more2023-11-01
CVE-2023-40110 CVE-2023-40110: In multiple functions of MtpPacket
In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21000P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21000 CVE-2023-21000: In MediaCodec
In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0241P3UNKNOWN≥ 8.0:0, < 8.0:2020-08-01≥ 8.1:0, < 8.1:2020-08-01+2 more2020-08-01
CVE-2020-0241 CVE-2020-0241: In NuPlayerStreamListener of NuPlayerStreamListener
In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0437P3UNKNOWN≥ 8.1:0, < 8.1:2021-04-01≥ 9:0, < 9:2021-04-01+2 more2021-04-01
CVE-2021-0437 CVE-2021-0437: In setPlayPolicy of DrmPlugin
In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48548P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+2 more2025-09-01
CVE-2025-48548 CVE-2025-48548: In multiple functions of AppOpsControllerImpl
In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-40114P3UNKNOWN≥ 14-next:0, < 14-next:2023-11-01≥ 11:0, < 11:2023-11-01+4 more2023-11-01
CVE-2023-40114 CVE-2023-40114: In multiple functions of MtpFfsHandle
In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0312P4UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2021-0312 CVE-2021-0312: In WAVSource::read of WAVExtractor
In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0311P4UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2021-0311 CVE-2021-0311: In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue
In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv