cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 24 of 29
CVE-2023-20999P4UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20999 CVE-2023-20999: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20996P4UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20996 CVE-2023-20996: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20998P4UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20998 CVE-2023-20998: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20997P4UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20997 CVE-2023-20997: In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21240P4UNKNOWN≥ 11:0, < 11:2023-07-012023-07-01
CVE-2023-21240 CVE-2023-21240: In Policy of Policy In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21167P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21167 CVE-2023-21167: In setProfileName of DevicePolicyManagerService In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21111P4UNKNOWN≥ 14-next:0, < 14-next:2023-11-01≥ 11:0, < 11:2023-11-01+3 more2023-11-01
CVE-2023-21111 CVE-2023-21111: In multiple functions of PhoneAccountRegistrar In multiple functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48644P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2025-48644 CVE-2025-48644: In multiple locations, there is a possible persistent denial of service due to improper input validation In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21029P4UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21029 CVE-2023-21029: In register of UidObserverController In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48559P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48559 CVE-2025-48559: In multiple functions of AppOpsService In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23712P4UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 12:0, < 12:2024-04-01+3 more2024-04-01
CVE-2024-23712 CVE-2024-23712: In multiple functions of AppOpsService In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48562P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48562 CVE-2025-48562: In writeContent of RemotePrintDocument In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-40659P4UNKNOWN≥ 15-next:0, < 15-next:2024-09-012024-09-01
CVE-2024-40659 CVE-2024-40659: In getRegistration of RemoteProvisioningService In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48603P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48603 CVE-2025-48603: In InputMethodInfo of InputMethodInfo In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26449P4UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26449 CVE-2025-26449: In multiple locations, there is a possible permanent denial of service due to resource exhaustion In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26432P4UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-012025-06-01
CVE-2025-26432 CVE-2025-26432: In multiple locations, there is a possible way to persistently DoS the device due to a missing length check In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26429P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26429 CVE-2025-26429: In collectOps of AppOpsService In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48551P4UNKNOWN≥ 13:0, < 13:2025-09-012025-09-01
CVE-2025-48551 CVE-2025-48551: In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused deputy In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20914P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-012023-05-01
CVE-2023-20914 CVE-2023-20914: In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20494P4UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2022-20494 CVE-2022-20494: In AutomaticZenRule of AutomaticZenRule In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase