cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 13 of 29
CVE-2022-20197P3UNKNOWN≥ 13-next:0, < 13-next:2022-09-01≥ 10:0, < 10:2022-09-01+3 more2022-09-01
CVE-2022-20197 CVE-2022-20197: In recycle of Parcel In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20192P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20192 CVE-2022-20192: In grantEmbeddedWindowFocus of WindowManagerService In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedded hierarchy due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0024P3UNKNOWN≥ 14-next:0, < 14-next:2024-05-01≥ 12:0, < 12:2024-05-01+3 more2024-05-01
CVE-2024-0024 CVE-2024-0024: In multiple methods of UserManagerService In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20356P3UNKNOWN≥ 11:0, < 11:2022-08-01≥ 12:0, < 12:2022-08-01+1 more2022-08-01
CVE-2022-20356 CVE-2022-20356: In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0923P3UNKNOWN≥ 12:0, < 12:2021-11-012021-11-01
CVE-2021-0923 CVE-2021-0923: In createOrUpdate of Permission In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0694P3UNKNOWN≥ 11:0, < 11:2022-04-012022-04-01
CVE-2021-0694 CVE-2021-0694: In setServiceForegroundInnerLocked of ActiveServices In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0486P3UNKNOWN≥ 10:0, < 10:2021-07-01≥ 11:0, < 11:2021-07-012021-07-01
CVE-2021-0486 CVE-2021-0486: In onPackageAddedInternal of PermissionManagerService In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0571P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0571 CVE-2021-0571: In ActivityTaskManagerService In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0547P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0547 CVE-2021-0547: In onReceive of NetInitiatedActivity In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in some HAL implementations with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20971P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20971 CVE-2023-20971: In updatePermissionTreeSourcePackage of PermissionManagerServiceImpl In updatePermissionTreeSourcePackage of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20415P3UNKNOWN≥ 10:0, < 10:2022-10-01≥ 11:0, < 11:2022-10-01+3 more2022-10-01
CVE-2022-20415 CVE-2022-20415: In handleFullScreenIntent of StatusBarNotificationActivityStarter In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass of the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0922P3UNKNOWN≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0922 CVE-2021-0922: In enforceCrossUserOrProfilePermission of PackageManagerService In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0999P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0999 CVE-2021-0999: In the broadcast definition in AndroidManifest In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20392P3UNKNOWN≥ 13-next:0, < 13-next:2022-09-01≥ 10:0, < 10:2022-09-01+3 more2022-09-01
CVE-2022-20392 CVE-2022-20392: In declareDuplicatePermission of ParsedPermissionUtils In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20204P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20204 CVE-2022-20204: In registerRemoteBugreportReceivers of DevicePolicyManagerService In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21088P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 12:0, < 12:2023-04-01+2 more2023-04-01
CVE-2023-21088 CVE-2023-21088: In deliverOnFlushComplete of LocationProviderManager In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20906P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+3 more2023-03-01
CVE-2023-20906 CVE-2023-20906: In onPackageAddedInternal of PermissionManagerService In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher Target SDK with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20993P3UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-20993 CVE-2023-20993: In multiple functions of SnoozeHelper In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21099P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21099 CVE-2023-21099: In multiple methods of PackageInstallerSession In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21017P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21017 CVE-2023-21017: In InstallStart of InstallStart In InstallStart of InstallStart.java, there is a possible way to change the installer package name due to an improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase