cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 21 of 29
CVE-2022-20511P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20511 CVE-2022-20511: In getNearbyAppStreamingPolicy of DevicePolicyManagerService In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0419P4UNKNOWN≥ 8.1:0, < 8.1:2020-10-01≥ 9:0, < 9:2020-10-01+1 more2020-10-01
CVE-2020-0419 CVE-2020-0419: In generateInfo of PackageInstallerSession In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0047P4UNKNOWN≥ 14-next:0, < 14-next:2024-03-01≥ 14:0, < 14:2024-03-012024-03-01
CVE-2024-0047 CVE-2024-0047: In writeUserLP of UserManagerService In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0468P4UNKNOWN≥ 10:0, < 10:2020-12-01≥ 11:0, < 11:2020-12-012020-12-01
CVE-2020-0468 CVE-2020-0468: In listen() and related functions of TelephonyRegistry In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0599P4UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 11:0, < 11:2021-07-012021-07-01
CVE-2021-0599 CVE-2021-0599: In scheduleTimeoutLocked of NotificationRecord In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadcasted intent due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20011P4UNKNOWN≥ 10:0, < 10:2022-05-01≥ 11:0, < 11:2022-05-01+2 more2022-05-01
CVE-2022-20011 CVE-2022-20011: In getArray of NotificationManagerService In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0704P4UNKNOWN≥ 9:0, < 9:2021-12-01≥ 10:0, < 10:2021-12-01+1 more2021-12-01
CVE-2021-0704 CVE-2021-0704: In createNoCredentialsPermissionNotification and related functions of AccountManagerService In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40075P4UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 11:0, < 11:2023-12-01+4 more2023-12-01
CVE-2023-40075 CVE-2023-40075: In forceReplaceShortcutInner of ShortcutPackage In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0653P4UNKNOWN≥ 9:0, < 9:2021-11-01≥ 10:0, < 10:2021-11-01+1 more2021-11-01
CVE-2021-0653 CVE-2021-0653: In enqueueNotification of NetworkPolicyManagerService In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0693P4UNKNOWN≥ 11:0, < 11:2021-09-012021-09-01
CVE-2021-0693 CVE-2021-0693: In openFile of HeapDumpProvider In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0644P4UNKNOWN≥ 10:0, < 10:2021-09-01≥ 11:0, < 11:2021-09-012021-09-01
CVE-2021-0644 CVE-2021-0644: In conditionallyRemoveIdentifiers of SubscriptionController In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0682P4UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 11:0, < 11:2021-09-012021-09-01
CVE-2021-0682 CVE-2021-0682: In sendAccessibilityEvent of NotificationManagerService In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21283P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 11:0, < 11:2023-08-01+2 more2023-08-01
CVE-2023-21283 CVE-2023-21283: In multiple functions of StatusHints In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0428P4UNKNOWN≥ 10:0, < 10:2021-09-012021-09-01
CVE-2021-0428 CVE-2021-0428: In getSimSerialNumber of TelephonyManager In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0979P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0979 CVE-2021-0979: In isRequestPinItemSupported of ShortcutService In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21105P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+2 more2023-06-01
CVE-2023-21105 CVE-2023-21105: In multiple functions of ChooserActivity In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20115P4UNKNOWN≥ 12:0, < 12:2022-05-01≥ 12L:0, < 12L:2022-05-012022-05-01
CVE-2022-20115 CVE-2022-20115: In broadcastServiceStateChanged of TelephonyRegistry In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20350P4UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20350 CVE-2022-20350: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43086P4UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43086 CVE-2024-43086: In validateAccountsInternal of AccountManagerService In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48590P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48590 CVE-2025-48590: In verifyAndGetBypass of AppOpsService In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase