cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 22 of 29
CVE-2023-21276P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 12:0, < 12:2023-08-01+2 more2023-08-01
CVE-2023-21276 CVE-2023-21276: In writeToParcel of CursorWindow In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21239P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 12:0, < 12:2023-07-01+2 more2023-07-01
CVE-2023-21239 CVE-2023-21239: In visitUris of Notification In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20352P4UNKNOWN≥ 12:0, < 12:2022-08-01≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20352 CVE-2022-20352: In addProviderRequestListener of LocationManagerService In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21143P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21143 CVE-2023-21143: In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21142P4UNKNOWN≥ 12:0, < 12:2023-06-01≥ 12L:0, < 12L:2023-06-012023-06-01
CVE-2023-21142 CVE-2023-21142: In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21104P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 12L:0, < 12L:2023-05-01+1 more2023-05-01
CVE-2023-21104 CVE-2023-21104: In applySyncTransaction of WindowOrganizer In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26463P4UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26463 CVE-2025-26463: In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48576P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48576 CVE-2025-48576: In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34742P4UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 14:0, < 14:2024-08-012024-08-01
CVE-2024-34742 CVE-2024-34742: In shouldWrite of OwnersData In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22431P4UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22431 CVE-2025-22431: In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no additional execution privileges needed. User interaction is not needed fo
osv
CVE-2025-48607P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+1 more2025-12-01
CVE-2025-48607 CVE-2025-48607: In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20219P4UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-01+2 more2022-07-01
CVE-2022-20219 CVE-2022-20219: In multiple functions of StorageManagerService In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48601P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48601 CVE-2025-48601: In multiple locations, there is a possible permanent denial of service due to improper input validation In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0480P4UNKNOWN≥ 8.1:0, < 8.1:2021-05-01≥ 9:0, < 9:2021-05-01+2 more2021-05-01
CVE-2021-0480 CVE-2021-0480: In createPendingIntent of SnoozeHelper In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0258P4UNKNOWN≥ 10:0, < 10:2020-08-012020-08-01
CVE-2020-0258 CVE-2020-0258: In stopZygoteLocked of AppZygote In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0239P4UNKNOWN≥ 9:0, < 9:2020-08-01≥ 10:0, < 10:2020-08-012020-08-01
CVE-2020-0239 CVE-2020-0239: In getDocumentMetadata of DocumentsContract In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This could lead to local information disclosure from a file (eg. a photo) containing location metadata with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0248P4UNKNOWN≥ 10:0, < 10:2020-08-012020-08-01
CVE-2020-0248 CVE-2020-0248: In postInstantAppNotif of InstantAppNotifier In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21284P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 11:0, < 11:2023-08-01+3 more2023-08-01
CVE-2023-21284 CVE-2023-21284: In multiple functions of DevicePolicyManager In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43090P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2024-43090 CVE-2024-43090: In multiple locations, there is a possible cross-user image read due to a missing permission check In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20482P4UNKNOWN≥ 12:0, < 12:2022-12-01≥ 12L:0, < 12L:2022-12-01+1 more2022-12-01
CVE-2022-20482 CVE-2022-20482: In createNotificationChannel of NotificationManager In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase