Platform Frameworks Native vulnerabilities

50 known vulnerabilities affecting platform/frameworks_native.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50

Vulnerabilities

Page 2 of 3
CVE-2023-21118UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21118 CVE-2023-21118: In unflattenString8 of Sensor In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39617UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+2 more2023-05-01
CVE-2021-39617 CVE-2021-39617: In multiple buttons of grant_permissions In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20444UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+1 more2023-05-01
CVE-2022-20444 CVE-2022-20444: In several functions of inputDispatcher In several functions of inputDispatcher.cpp, there is a possible way to make toasts clickable due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21094UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21094 CVE-2023-21094: In sanitize of LayerState In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21034UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21034 CVE-2023-21034: In multiple functions of SensorService In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20540UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20540 CVE-2022-20540: In SurfaceFlinger::doDump of SurfaceFlinger In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20554UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20554 CVE-2022-20554: In removeEventHubDevice of InputDevice In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20357UNKNOWN≥ 12:0, < 12:2022-08-01≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20357 CVE-2022-20357: In writeToParcel of SurfaceControl In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20344UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20344 CVE-2022-20344: In stealReceiveChannel of EventThread In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20226UNKNOWN≥ 12:0, < 12:2022-07-01≥ 12L:0, < 12L:2022-07-012022-07-01
CVE-2022-20226 CVE-2022-20226: In finishDrawingWindow of WindowManagerService In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20201UNKNOWN≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20201 CVE-2022-20201: In getAppSize of InstalldNativeService In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39691UNKNOWN≥ 10:0, < 10:2022-06-01≥ 11:0, < 11:2022-06-012022-06-01
CVE-2021-39691 CVE-2021-39691: In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39690UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39690 CVE-2021-39690: In setDisplayPadding of WallpaperManagerService In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39620UNKNOWN≥ 11:0, < 11:2022-01-01≥ 12:0, < 12:2022-01-012022-01-01
CVE-2021-39620 CVE-2021-39620: In ipcSetDataReference of Parcel In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1028UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1028 CVE-2021-1028: In setClientStateLocked of SurfaceFlinger In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1027UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1027 CVE-2021-1027: In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1029UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1029 CVE-2021-1029: In setClientStateLocked of SurfaceFlinger In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0919UNKNOWN≥ 10:0, < 10:2021-11-01≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0919 CVE-2021-0919: In getService of IServiceManager In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0684UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0684 CVE-2021-0684: In TouchInputMapper::sync of TouchInputMapper In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0394UNKNOWN≥ 11:0, < 11:2021-03-012021-03-01
CVE-2021-0394 CVE-2021-0394: In android_os_Parcel_readString8 of android_os_Parcel In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv