Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 23 of 29
CVE-2020-0389P4UNKNOWN≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0389 CVE-2020-0389: In createSaveNotification of RecordingService
In createSaveNotification of RecordingService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0500P4UNKNOWN≥ 10:0, < 10:2022-09-01≥ 11:0, < 11:2022-09-012022-09-01
CVE-2020-0500 CVE-2020-0500: In startInputUncheckedLocked of InputMethodManagerService
In startInputUncheckedLocked of InputMethodManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0931P4UNKNOWN≥ 9:0, < 9:2021-11-01≥ 10:0, < 10:2021-11-01+2 more2021-11-01
CVE-2021-0931 CVE-2021-0931: In getAlias of BluetoothDevice
In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs due to missing data filtering. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39664P4UNKNOWN≥ 12:0, < 12:2022-02-012022-02-01
CVE-2021-39664 CVE-2021-39664: In LoadedPackage::Load of LoadedArsc
In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure when parsing an APK file with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20199P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20199 CVE-2022-20199: In multiple locations of NfcService
In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20510P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20510 CVE-2022-20510: In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService
In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the notification streaming policy of other users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0521P4UNKNOWN≥ 8.1:0, < 8.1:2021-06-01≥ 9:0, < 9:2021-06-01+2 more2021-06-01
CVE-2021-0521 CVE-2021-0521: In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check
In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of cross-user permissions with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0986P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0986 CVE-2021-0986: In hasGrantedPolicy of DevicePolicyManagerService
In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device admin due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0572P4UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0572 CVE-2021-0572: In doNotification of AccountManagerService
In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0554P4UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0554 CVE-2021-0554: In isBackupServiceActive of BackupManagerService
In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21136P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21136 CVE-2023-21136: In multiple functions of JobStore
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31314P4UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31314 CVE-2024-31314: In multiple functions of ShortcutService
In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20466P4UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20466 CVE-2022-20466: In applyKeyguardFlags of NotificationShadeWindowControllerImpl
In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1011P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1011 CVE-2021-1011: In setPackageStoppedState of PackageManagerService
In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1010P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1010 CVE-2021-1010: In getSigningKeySet of PackageManagerService
In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1025P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1025 CVE-2021-1025: In hasNamedWallpaper of WallpaperManagerService
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0686P4UNKNOWN≥ 10:0, < 10:2021-09-01≥ 11:0, < 11:2021-09-012021-09-01
CVE-2021-0686 CVE-2021-0686: In getDefaultSmsPackage of RoleManagerService
In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20206P4UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20206 CVE-2022-20206: In setPackageOrComponentEnabled of NotificationManagerService
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0019P4UNKNOWN≥ 14-next:0, < 14-next:2024-01-01≥ 12:0, < 12:2024-01-01+3 more2024-01-01
CVE-2024-0019 CVE-2024-0019: In setListening of AppOpsControllerImpl
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a missing check for active recordings. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-49740P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2024-49740 CVE-2024-49740: In multiple locations, there is a possible crash loop due to resource exhaustion
In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv