Platform Frameworks Native vulnerabilities
50 known vulnerabilities affecting platform/frameworks_native.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50
Vulnerabilities
Page 2 of 3
CVE-2020-0226P3UNKNOWN≥ 10:0, < 10:2020-07-012020-07-01
CVE-2020-0226 CVE-2020-0226: In createWithSurfaceParent of Client
In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0392P3UNKNOWN≥ 9:0, < 9:2020-09-01≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0392 CVE-2020-0392: In getLayerDebugInfo of SurfaceFlinger
In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0318P3UNKNOWN≥ 8.1:0, < 8.1:2021-01-01≥ 9:0, < 9:2021-01-01+2 more2021-01-01
CVE-2021-0318 CVE-2021-0318: In appendEventsToCacheLocked of SensorEventConnection
In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0332P3UNKNOWN≥ 10:0, < 10:2021-02-01≥ 11:0, < 11:2021-02-012021-02-01
CVE-2021-0332 CVE-2021-0332: In bootFinished of SurfaceFlinger
In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0310P3UNKNOWN≥ 11:0, < 11:2021-01-012021-01-01
CVE-2021-0310 CVE-2021-0310: In LazyServiceRegistrar of LazyServiceRegistrar
In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0420P3UNKNOWN≥ 11:0, < 11:2020-10-012020-10-01
CVE-2020-0420 CVE-2020-0420: In setUpdatableDriverPath of GpuService
In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1028P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1028 CVE-2021-1028: In setClientStateLocked of SurfaceFlinger
In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1029P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1029 CVE-2021-1029: In setClientStateLocked of SurfaceFlinger
In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21034P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21034 CVE-2023-21034: In multiple functions of SensorService
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39620P3UNKNOWN≥ 11:0, < 11:2022-01-01≥ 12:0, < 12:2022-01-012022-01-01
CVE-2021-39620 CVE-2021-39620: In ipcSetDataReference of Parcel
In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0684P3UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0684 CVE-2021-0684: In TouchInputMapper::sync of TouchInputMapper
In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48639P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48639 CVE-2025-48639: In DefaultTransitionHandler
In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39691P3UNKNOWN≥ 10:0, < 10:2022-06-01≥ 11:0, < 11:2022-06-012022-06-01
CVE-2021-39691 CVE-2021-39691: In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input
In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-40131P4UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 12:0, < 12:2023-10-01+2 more2023-10-01
CVE-2023-40131 CVE-2023-40131: In GpuService of GpuService
In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20344P4UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20344 CVE-2022-20344: In stealReceiveChannel of EventThread
In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20554P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20554 CVE-2022-20554: In removeEventHubDevice of InputDevice
In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20201P4UNKNOWN≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20201 CVE-2022-20201: In getAppSize of InstalldNativeService
In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21171P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21171 CVE-2023-21171: In verifyInputEvent of InputDispatcher
In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to side channel information disclosure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0394P4UNKNOWN≥ 11:0, < 11:2021-03-012021-03-01
CVE-2021-0394 CVE-2021-0394: In android_os_Parcel_readString8 of android_os_Parcel
In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21118P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21118 CVE-2023-21118: In unflattenString8 of Sensor
In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv