cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 9 of 29
CVE-2023-35676P3UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 12:0, < 12:2023-09-01+2 more2023-09-01
CVE-2023-35676 CVE-2023-35676: In createQuickShareAction of SaveImageInBackgroundTask In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21254P3UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 13:0, < 13:2023-07-012023-07-01
CVE-2023-21254 CVE-2023-21254: In getCurrentState of OneTimePermissionUserManager In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21192P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21192 CVE-2023-21192: In setInputMethodWithSubtypeIdLocked of InputMethodManagerService In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21081P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21081 CVE-2023-21081: In multiple functions of PackageInstallerService In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21245P3UNKNOWN≥ 14-next:0, < 14-next:2024-01-01≥ 11:0, < 11:2024-01-01+4 more2024-01-01
CVE-2023-21245 CVE-2023-21245: In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20934P3UNKNOWN≥ 12:0, < 12:2023-02-01≥ 12L:0, < 12L:2023-02-01+1 more2023-02-01
CVE-2023-20934 CVE-2023-20934: In resolveAttributionSource of ServiceUtilities In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21110P3UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21110 CVE-2023-21110: In several functions of SnoozeHelper In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21257P3UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 13:0, < 13:2023-07-012023-07-01
CVE-2023-21257 CVE-2023-21257: In updateSettingsInternalLI of InstallPackageHelper In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21128P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21128 CVE-2023-21128: In various functions of AppStandbyController In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20450P3UNKNOWN≥ 11:0, < 11:2022-11-01≥ 12:0, < 12:2022-11-01+2 more2022-11-01
CVE-2022-20450 CVE-2022-20450: In restorePermissionState of PermissionManagerServiceImpl In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49735P3UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 15:0, < 15:2025-01-012025-01-01
CVE-2024-49735 CVE-2024-49735: In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0441P3UNKNOWN≥ 11-next:0, < 11-next:2020-11-01≥ 8.0:0, < 8.0:2020-11-01+4 more2020-11-01
CVE-2020-0441 CVE-2020-0441: In Message and toBundle of Notification In Message and toBundle of Notification.java, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service requiring a device reset to fix with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21144P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21144 CVE-2023-21144: In doInBackground of NotificationContentInflater In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0108P3UNKNOWN≥ 8.1:0, < 8.1:2020-08-01≥ 9:0, < 9:2020-08-01+1 more2020-08-01
CVE-2020-0108 CVE-2020-0108: In postNotification of ServiceRecord In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0928P3UNKNOWN≥ 9:0, < 9:2021-11-01≥ 10:0, < 10:2021-11-01+1 more2021-11-01
CVE-2021-0928 CVE-2021-0928: In createFromParcel of OutputConfiguration In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23705P3UNKNOWN≥ 14-next:0, < 14-next:2024-05-01≥ 12:0, < 12:2024-05-01+3 more2024-05-01
CVE-2024-23705 CVE-2024-23705: In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0401P3UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0401 CVE-2020-0401: In setInstallerPackageName of PackageManagerService In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20489P3UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2022-20489 CVE-2022-20489: In many functions of AutomaticZenRule In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20492P3UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2022-20492 CVE-2022-20492: In many functions of AutomaticZenRule In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20490P3UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2022-20490 CVE-2022-20490: In multiple functions of AutomaticZenRule In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase