cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 12 of 29
CVE-2021-39693P3UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39693 CVE-2021-39693: In onUidStateChanged of AppOpsService In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0921P3UNKNOWN≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0921 CVE-2021-0921: In ParsingPackageImpl of ParsingPackageImpl In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0398P3UNKNOWN≥ 11:0, < 11:2021-03-012021-03-01
CVE-2021-0398 CVE-2021-0398: In bindServiceLocked of ActiveServices In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20475P3UNKNOWN≥ 11:0, < 11:2022-12-01≥ 12:0, < 12:2022-12-01+2 more2022-12-01
CVE-2022-20475 CVE-2022-20475: In test of ResetTargetTaskHelper In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20917P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+3 more2023-03-01
CVE-2023-20917 CVE-2023-20917: In onTargetSelected of ResolverActivity In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39630P3UNKNOWN≥ 12:0, < 12:2022-01-012022-01-01
CVE-2021-39630 CVE-2021-39630: In executeRequest of OverlayManagerService In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39676P3UNKNOWN≥ 11:0, < 11:2022-02-012022-02-01
CVE-2021-39676 CVE-2021-39676: In writeThrowable of AndroidFuture In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0649P3UNKNOWN≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0649 CVE-2021-0649: In stopVpnProfile of Vpn In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39703P3UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39703 CVE-2021-39703: In updateState of UsbDeviceManager In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0932P3UNKNOWN≥ 10:0, < 10:2021-11-012021-11-01
CVE-2021-0932 CVE-2021-0932: In showNotification of NavigationModeController In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20964P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 12:0, < 12:2023-03-01+2 more2023-03-01
CVE-2023-20964 CVE-2023-20964: In multiple functions of MediaSessionRecord In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0799P3UNKNOWN≥ 12:0, < 12:2021-11-012021-11-01
CVE-2021-0799 CVE-2021-0799: In ActivityThread In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0439P3UNKNOWN≥ 11:0, < 11:2021-04-012021-04-01
CVE-2021-0439 CVE-2021-0439: In setPowerModeWithHandle of com_android_server_power_PowerManagerService In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0442P3UNKNOWN≥ 11:0, < 11:2021-04-012021-04-01
CVE-2021-0442 CVE-2021-0442: In updateInfo of android_hardware_input_InputApplicationHandle In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31315P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31315 CVE-2024-31315: In multiple functions of ManagedServices In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20441P3UNKNOWN≥ 10:0, < 10:2022-11-01≥ 11:0, < 11:2022-11-01+3 more2022-11-01
CVE-2022-20441 CVE-2022-20441: In navigateUpTo of Task In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0981P3UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-012022-07-01
CVE-2021-0981 CVE-2021-0981: In enqueueNotificationInternal of NotificationManagerService In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a foreground service without showing a notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1003P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1003 CVE-2021-1003: In adjustStreamVolume of AudioService In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39799P3UNKNOWN≥ 12:0, < 12:2022-04-01≥ 12L:0, < 12L:2022-04-012022-04-01
CVE-2021-39799 CVE-2021-39799: In AttributionSource of AttributionSource In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39797P3UNKNOWN≥ 12:0, < 12:2022-04-01≥ 12L:0, < 12L:2022-04-012022-04-01
CVE-2021-39797 CVE-2021-39797: In several functions of of LauncherApps In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase