Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 25 of 29
CVE-2020-0443P4UNKNOWN≥ 11-next:0, < 11-next:2020-11-01≥ 8.0:0, < 8.0:2020-11-01+4 more2020-11-01
CVE-2020-0443 CVE-2020-0443: In LocaleList of LocaleList
In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of service requiring factory reset to restore with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39670P4UNKNOWN≥ 12:0, < 12:2022-05-01≥ 12L:0, < 12L:2022-05-012022-05-01
CVE-2021-39670 CVE-2021-39670: In setStream of WallpaperManager
In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0322P4UNKNOWN≥ 9:0, < 9:2021-01-01≥ 10:0, < 10:2021-01-01+1 more2021-01-01
CVE-2021-0322 CVE-2021-0322: In onCreate of SlicePermissionActivity
In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20476P4UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+2 more2022-12-01
CVE-2022-20476 CVE-2022-20476: In setEnabledSetting of PackageManager
In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0321P4UNKNOWN≥ 11:0, < 11:2021-01-012021-01-01
CVE-2021-0321 CVE-2021-0321: In enforceDumpPermissionForPackage of ActivityManagerService
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0338P4UNKNOWN≥ 10:0, < 10:2021-02-01≥ 11:0, < 11:2021-02-012021-02-01
CVE-2021-0338 CVE-2021-0338: In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings
In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2019-9376P4UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+1 more2021-01-01
CVE-2019-9376 CVE-2019-9376: In Account of Account
In Account of Account.java, there is a possible boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20414P4UNKNOWN≥ 10:0, < 10:2022-11-01≥ 11:0, < 11:2022-11-01+3 more2022-11-01
CVE-2022-20414 CVE-2022-20414: In setImpl of AlarmManagerService
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20922P4UNKNOWN≥ 11:0, < 11:2023-01-01≥ 12:0, < 12:2023-01-01+2 more2023-01-01
CVE-2023-20922 CVE-2023-20922: In setMimeGroup of PackageManagerService
In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1030P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1030 CVE-2021-1030: In setNotificationsShownFromListener of NotificationManagerService
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1013P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1013 CVE-2021-1013: In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat
osv
CVE-2021-0997P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0997 CVE-2021-0997: In handleUpdateNetworkState of GnssNetworkConnectivityHandler
In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1009P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1009 CVE-2021-1009: In setApplicationCategoryHint of PackageManagerService
In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21243P4UNKNOWN≥ 11:0, < 11:2023-07-012023-07-01
CVE-2023-21243 CVE-2023-21243: In validateForCommonR1andR2 of PasspointConfiguration
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-0027P4UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 12:0, < 12:2024-04-01+3 more2024-04-01
CVE-2024-0027 CVE-2024-0027: In multiple functions of SnoozeHelper
In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20129P4UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 10:0, < 10:2022-06-01+3 more2022-06-01
CVE-2022-20129 CVE-2022-20129: In registerPhoneAccount of PhoneAccountRegistrar
In registerPhoneAccount of PhoneAccountRegistrar.java, there is a possible way to prevent the user from selecting a phone account due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20355P4UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20355 CVE-2022-20355: In get of PacProxyService
In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21103P4UNKNOWN≥ 14-next:0, < 14-next:2023-11-01≥ 11:0, < 11:2023-11-01+3 more2023-11-01
CVE-2023-21103 CVE-2023-21103: In registerPhoneAccount of PhoneAccountRegistrar
In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48550P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48550 CVE-2025-48550: In testGrantSlicePermission of SliceManagerTest
In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21087P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 11:0, < 11:2023-07-01+3 more2023-07-01
CVE-2023-21087 CVE-2023-21087: In PreferencesHelper
In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv