cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 29 of 29
CVE-2022-20543P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20543 CVE-2022-20543: In multiple locations, there is a possible display crash loop due to improper input validation In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0382P4UNKNOWN≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0382 CVE-2020-0382: In RunInternal of dumpstate In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20559P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20559 CVE-2022-20559: In revokeOwnPermissionsOnKill of PermissionManager In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0983P4UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2021-0983 CVE-2021-0983: In createAdminSupportIntent of DevicePolicyManagerService In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1018P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1018 CVE-2021-1018: In adjustStreamVolume of AudioService In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1032P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1032 CVE-2021-1032: In getMimeGroup of PackageManagerService In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0988P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0988 CVE-2021-0988: In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1031P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1031 CVE-2021-1031: In cancelNotificationsFromListener of NotificationManagerService In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0978P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0978 CVE-2021-0978: In getSerialForPackage of DeviceIdentifiersPolicyService In getSerialForPackage of DeviceIdentifiersPolicyService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49743UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+4 more2025-02-01
CVE-2024-49743 CVE-2024-49743: In multiple locations, there is a possible way to launch an activity from the background due to BAL Bypass In multiple locations, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0100UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+4 more2025-02-01
CVE-2025-0100 CVE-2025-0100: In onCreate of MediaProjectionPermissionActivity In onCreate of MediaProjectionPermissionActivity.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0097UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 15:0, < 15:2025-02-012025-02-01
CVE-2025-0097 CVE-2025-0097: In transferTouchGesture of WindowManagerService In transferTouchGesture of WindowManagerService.java , there is a possible way to steal sensitive user input due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49741UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+4 more2025-02-01
CVE-2024-49741 CVE-2024-49741: In multiple functions of AppWidgetServiceImpl In multiple functions of AppWidgetServiceImpl.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0098UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 15:0, < 15:2025-02-012025-02-01
CVE-2025-0098 CVE-2025-0098: In multiple functions of TaskFragmentOrganizerController In multiple functions of TaskFragmentOrganizerController.java, there is a possible token leak due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0099UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 15:0, < 15:2025-02-012025-02-01
CVE-2025-0099 CVE-2025-0099: In multiple functions of CompanionDeviceManagerService In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49721UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+2 more2025-02-01
CVE-2024-49721 CVE-2024-49721: In InputMethodSubtypeArray of InputMethodSubtypeArray In InputMethodSubtypeArray of InputMethodSubtypeArray.java, there is a possible way to bypass a key intent check to launch arbitrary activity due to Parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34735UNKNOWN≥ 12:0, < 12:2024-08-01≥ 12L:0, < 12L:2024-08-01+1 more2024-08-01
CVE-2024-34735 CVE-2024-34735: In multiple locations, there is a possible background activity launch due to a logic error in the code In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39617UNKNOWN≥ 11:0, < 11:2023-05-01≥ 12:0, < 12:2023-05-012023-05-01
CVE-2021-39617 CVE-2021-39617: In multiple buttons of grant_permissions In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20444UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+1 more2023-05-01
CVE-2022-20444 CVE-2022-20444: In several functions of inputDispatcher In several functions of inputDispatcher.cpp, there is a possible way to make toasts clickable due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase