cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 26 of 29
CVE-2023-21026P4UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21026 CVE-2023-21026: In updateInputChannel of WindowManagerService In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20426P4UNKNOWN≥ 10:0, < 10:2022-11-01≥ 11:0, < 11:2022-11-01+3 more2022-11-01
CVE-2022-20426 CVE-2022-20426: In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21177P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21177 CVE-2023-21177: In requestAppKeyboardShortcuts of WindowManagerService In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21280P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 12:0, < 12:2023-08-01+2 more2023-08-01
CVE-2023-21280 CVE-2023-21280: In setMediaButtonBroadcastReceiver of MediaSessionRecord In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20930P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-20930 CVE-2023-20930: In pushDynamicShortcut of ShortcutPackage In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48542P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48542 CVE-2025-48542: In multiple functions of AccountManagerService In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2019-2219P4UNKNOWN≥ 11:0, < 11:2021-05-052021-05-01
CVE-2019-2219 CVE-2019-2219: In several functions of NotificationManagerService In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0247P4UNKNOWN≥ 8.0:0, < 8.0:2020-08-01≥ 8.1:0, < 8.1:2020-08-01+1 more2020-08-01
CVE-2020-0247 CVE-2020-0247: In Threshold::getHistogram of ImageProcessHelper In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0469P4UNKNOWN≥ 11:0, < 11:2020-12-012020-12-01
CVE-2020-0469 CVE-2020-0469: In addEscrowToken of LockSettingsService In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password due to logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20425P4UNKNOWN≥ 10:0, < 10:2022-10-01≥ 11:0, < 11:2022-10-01+3 more2022-10-01
CVE-2022-20425 CVE-2022-20425: In addAutomaticZenRule of ZenModeHelper In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20500P4UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20500 CVE-2022-20500: In loadFromXml of ShortcutPackage In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0651P4UNKNOWN≥ 12-next:0, < 12-next:2021-10-01≥ 9:0, < 9:2021-10-01+3 more2021-10-01
CVE-2021-0651 CVE-2021-0651: In loadLabel of PackageItemInfo In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20455P4UNKNOWN≥ 10:0, < 10:2023-02-01≥ 11:0, < 11:2023-02-01+3 more2023-02-01
CVE-2022-20455 CVE-2022-20455: In addAutomaticZenRule of ZenModeHelper In addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21137P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21137 CVE-2023-21137: In several methods of JobStore In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39624P4UNKNOWN≥ 11:0, < 11:2022-10-01≥ 12:0, < 12:2022-10-01+1 more2022-10-01
CVE-2021-39624 CVE-2021-39624: In freeStageDirs PackageInstallerService In freeStageDirs PackageInstallerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20143P4UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 10:0, < 10:2022-06-01+3 more2022-06-01
CVE-2022-20143 CVE-2022-20143: In addAutomaticZenRule of ZenModeHelper In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20394P4UNKNOWN≥ 10:0, < 10:2022-10-01≥ 11:0, < 11:2022-10-01+2 more2022-10-01
CVE-2022-20394 CVE-2022-20394: In getInputMethodWindowVisibleHeight of InputMethodManagerService In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-0026P4UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 12:0, < 12:2024-04-01+3 more2024-04-01
CVE-2024-0026 CVE-2024-0026: In multiple functions of SnoozeHelper In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0934P4UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2021-0934 CVE-2021-0934: In findAllDeAccounts of AccountsDb In findAllDeAccounts of AccountsDb.java, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20465P4UNKNOWN≥ 10:0, < 10:2022-11-01≥ 11:0, < 11:2022-11-01+3 more2022-11-01
CVE-2022-20465 CVE-2022-20465: In dismiss and related functions of KeyguardHostViewController In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase