Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 10 of 29
CVE-2021-0327P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0327 CVE-2021-0327: In getContentProviderImpl of ActivityManagerService
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0306P3UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2021-0306 CVE-2021-0306: In addAllPermissions of PermissionManagerService
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0478P3UNKNOWN≥ 8.1:0, < 8.1:2021-06-05≥ 9:0, < 9:2021-06-05+2 more2021-06-01
CVE-2021-0478 CVE-2021-0478: In updateDrawable of StatusBarIconView
In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services without notifying the user, with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20456P3UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2022-20456 CVE-2022-20456: In AutomaticZenRule of AutomaticZenRule
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0683P3UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0683 CVE-2021-0683: In runTraceIpcStop of ActivityManagerShellCommand
In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0640P3UNKNOWN≥ 9:0, < 9:2021-08-01≥ 10:0, < 10:2021-08-01+1 more2021-08-01
CVE-2021-0640 CVE-2021-0640: In noteAtomLogged of StatsdStats
In noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20005P3UNKNOWN≥ 10:0, < 10:2022-05-01≥ 11:0, < 11:2022-05-01+2 more2022-05-01
CVE-2022-20005 CVE-2022-20005: In validateApkInstallLocked of PackageInstallerSession
In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0439P3UNKNOWN≥ 11-next:0, < 11-next:2020-11-01≥ 8.0:0, < 8.0:2020-11-01+4 more2020-11-01
CVE-2020-0439 CVE-2020-0439: In generatePackageInfo of PackageManagerService
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant apps, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20004P3UNKNOWN≥ 10:0, < 10:2022-05-01≥ 11:0, < 11:2022-05-01+2 more2022-05-01
CVE-2022-20004 CVE-2022-20004: In checkSlicePermission of SliceManagerService
In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0472P3UNKNOWN≥ 9:0, < 9:2021-05-01≥ 10:0, < 10:2021-05-01+1 more2021-05-01
CVE-2021-0472 CVE-2021-0472: In shouldLockKeyguard of LockTaskController
In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0513P3UNKNOWN≥ 8.1:0, < 8.1:2021-06-05≥ 9:0, < 9:2021-06-05+2 more2021-06-01
CVE-2021-0513 CVE-2021-0513: In deleteNotificationChannel and related functions of NotificationManagerService
In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20135P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 10:0, < 10:2022-06-01+3 more2022-06-01
CVE-2022-20135 CVE-2022-20135: In writeToParcel of GateKeeperResponse
In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0595P3UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0595 CVE-2021-0595: In lockAllProfileTasks of RootWindowContainer
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0685P3UNKNOWN≥ 11:0, < 11:2021-09-012021-09-01
CVE-2021-0685 CVE-2021-0685: In ParsedIntentInfo of ParsedIntentInfo
In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34739P3UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 13:0, < 13:2025-05-01+1 more2025-05-01
CVE-2024-34739 CVE-2024-34739: In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager
In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-40109P3UNKNOWN≥ 14-next:0, < 14-next:2023-11-01≥ 11:0, < 11:2023-11-01+4 more2023-11-01
CVE-2023-40109 CVE-2023-40109: In createFromParcel of UsbConfiguration
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0485P3UNKNOWN≥ 11:0, < 11:2021-05-012021-05-01
CVE-2021-0485 CVE-2021-0485: In getMinimalSize of PipBoundsAlgorithm
In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20470P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20470 CVE-2022-20470: In bindRemoteViewsService of AppWidgetServiceImpl
In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20911P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+3 more2023-03-01
CVE-2023-20911 CVE-2023-20911: In addPermission of PermissionManagerServiceImpl
In addPermission of PermissionManagerServiceImpl.java , there is a possible failure to persist permission settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0257P3UNKNOWN≥ 10:0, < 10:2020-08-012020-08-01
CVE-2020-0257 CVE-2020-0257: In SpecializeCommon of com_android_internal_os_Zygote
In SpecializeCommon of com_android_internal_os_Zygote.cpp, there is a permissions bypass due to an incomplete cleanup. This could lead to local escalation of privilege in isolated processes with no additional execution privileges needed. User interaction is not needed for exploitation.
osv