Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 11 of 29
CVE-2021-0652P3UNKNOWN≥ 12-next:0, < 12-next:2021-10-01≥ 8.1:0, < 8.1:2021-10-01+4 more2021-10-01
CVE-2021-0652 CVE-2021-0652: In VectorDrawable::VectorDrawable of VectorDrawable
In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20478P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20478 CVE-2022-20478: In NotificationChannel of NotificationChannel
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20479P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20479 CVE-2022-20479: In NotificationChannel of NotificationChannel
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20491P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20491 CVE-2022-20491: In NotificationChannel of NotificationChannel
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20495P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20495 CVE-2022-20495: In getEnabledAccessibilityServiceList of AccessibilityManager
In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0440P3UNKNOWN≥ 11:0, < 11:2020-12-012020-12-01
CVE-2020-0440 CVE-2020-0440: In createVirtualDisplay of DisplayManagerService
In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20484P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20484 CVE-2022-20484: In NotificationChannel of NotificationChannel
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20480P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20480 CVE-2022-20480: In NotificationChannel of NotificationChannel
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20124P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20124 CVE-2022-20124: In deletePackageX of DeletePackageHelper
In deletePackageX of DeletePackageHelper.java, there is a possible way for a Guest user to reset pre-loaded applications for other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0708P3UNKNOWN≥ 12-next:0, < 12-next:2021-10-01≥ 8.1:0, < 8.1:2021-10-01+4 more2021-10-01
CVE-2021-0708 CVE-2021-0708: In runDumpHeap of ActivityManagerShellCommand
In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20144P3UNKNOWN≥ 12:0, < 12:2022-12-01≥ 12L:0, < 12L:2022-12-01+1 more2022-12-01
CVE-2022-20144 CVE-2022-20144: In cropPhoto of EditUserPhotoController
In cropPhoto of EditUserPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20477P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20477 CVE-2022-20477: In shouldHideNotification of KeyguardNotificationVisibilityProvider
In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20919P3UNKNOWN≥ 13:0, < 13:2023-01-012023-01-01
CVE-2023-20919 CVE-2023-20919: In getStringsForPrefix of Settings
In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20512P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20512 CVE-2022-20512: In navigateUpTo of Task
In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0417P3UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+1 more2021-07-01
CVE-2020-0417 CVE-2020-0417: In setNiNotification of GpsNetInitiatedHandler
In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20920P3UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2023-20920 CVE-2023-20920: In queue of UsbRequest
In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39619P3UNKNOWN≥ 11:0, < 11:2022-02-01≥ 12:0, < 12:2022-02-012022-02-01
CVE-2021-39619 CVE-2021-39619: In updatePackageMappingsData of UsageStatsService
In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0957P3UNKNOWN≥ 10:0, < 10:2022-03-01≥ 11:0, < 11:2022-03-01+2 more2022-03-01
CVE-2021-0957 CVE-2021-0957: In NotificationStackScrollLayout of NotificationStackScrollLayout
In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset Protections. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39695P3UNKNOWN≥ 11:0, < 11:2022-03-012022-03-01
CVE-2021-39695 CVE-2021-39695: In createOrUpdate of BasePermission
In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0984P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0984 CVE-2021-0984: In onNullBinding of ManagedServices
In onNullBinding of ManagedServices.java, there is a possible permission bypass due to an incorrectly unbound service. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv