Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 12 of 29
CVE-2021-39693P3UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39693 CVE-2021-39693: In onUidStateChanged of AppOpsService
In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0921P3UNKNOWN≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0921 CVE-2021-0921: In ParsingPackageImpl of ParsingPackageImpl
In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0398P3UNKNOWN≥ 11:0, < 11:2021-03-012021-03-01
CVE-2021-0398 CVE-2021-0398: In bindServiceLocked of ActiveServices
In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20475P3UNKNOWN≥ 11:0, < 11:2022-12-01≥ 12:0, < 12:2022-12-01+2 more2022-12-01
CVE-2022-20475 CVE-2022-20475: In test of ResetTargetTaskHelper
In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20917P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+3 more2023-03-01
CVE-2023-20917 CVE-2023-20917: In onTargetSelected of ResolverActivity
In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39630P3UNKNOWN≥ 12:0, < 12:2022-01-012022-01-01
CVE-2021-39630 CVE-2021-39630: In executeRequest of OverlayManagerService
In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39676P3UNKNOWN≥ 11:0, < 11:2022-02-012022-02-01
CVE-2021-39676 CVE-2021-39676: In writeThrowable of AndroidFuture
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0649P3UNKNOWN≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0649 CVE-2021-0649: In stopVpnProfile of Vpn
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39703P3UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39703 CVE-2021-39703: In updateState of UsbDeviceManager
In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0932P3UNKNOWN≥ 10:0, < 10:2021-11-012021-11-01
CVE-2021-0932 CVE-2021-0932: In showNotification of NavigationModeController
In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20964P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 12:0, < 12:2023-03-01+2 more2023-03-01
CVE-2023-20964 CVE-2023-20964: In multiple functions of MediaSessionRecord
In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0799P3UNKNOWN≥ 12:0, < 12:2021-11-012021-11-01
CVE-2021-0799 CVE-2021-0799: In ActivityThread
In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0439P3UNKNOWN≥ 11:0, < 11:2021-04-012021-04-01
CVE-2021-0439 CVE-2021-0439: In setPowerModeWithHandle of com_android_server_power_PowerManagerService
In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0442P3UNKNOWN≥ 11:0, < 11:2021-04-012021-04-01
CVE-2021-0442 CVE-2021-0442: In updateInfo of android_hardware_input_InputApplicationHandle
In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31315P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31315 CVE-2024-31315: In multiple functions of ManagedServices
In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20441P3UNKNOWN≥ 10:0, < 10:2022-11-01≥ 11:0, < 11:2022-11-01+3 more2022-11-01
CVE-2022-20441 CVE-2022-20441: In navigateUpTo of Task
In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0981P3UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-012022-07-01
CVE-2021-0981 CVE-2021-0981: In enqueueNotificationInternal of NotificationManagerService
In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a foreground service without showing a notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1003P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1003 CVE-2021-1003: In adjustStreamVolume of AudioService
In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39799P3UNKNOWN≥ 12:0, < 12:2022-04-01≥ 12L:0, < 12L:2022-04-012022-04-01
CVE-2021-39799 CVE-2021-39799: In AttributionSource of AttributionSource
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39797P3UNKNOWN≥ 12:0, < 12:2022-04-01≥ 12L:0, < 12L:2022-04-012022-04-01
CVE-2021-39797 CVE-2021-39797: In several functions of of LauncherApps
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv