Platform Frameworks Native vulnerabilities
50 known vulnerabilities affecting platform/frameworks_native.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50
Vulnerabilities
Page 2 of 3
CVE-2023-21118UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21118 CVE-2023-21118: In unflattenString8 of Sensor
In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39617UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+2 more2023-05-01
CVE-2021-39617 CVE-2021-39617: In multiple buttons of grant_permissions
In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20444UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+1 more2023-05-01
CVE-2022-20444 CVE-2022-20444: In several functions of inputDispatcher
In several functions of inputDispatcher.cpp, there is a possible way to make toasts clickable due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21094UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21094 CVE-2023-21094: In sanitize of LayerState
In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21034UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21034 CVE-2023-21034: In multiple functions of SensorService
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20540UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20540 CVE-2022-20540: In SurfaceFlinger::doDump of SurfaceFlinger
In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20554UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20554 CVE-2022-20554: In removeEventHubDevice of InputDevice
In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20357UNKNOWN≥ 12:0, < 12:2022-08-01≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20357 CVE-2022-20357: In writeToParcel of SurfaceControl
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20344UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20344 CVE-2022-20344: In stealReceiveChannel of EventThread
In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20226UNKNOWN≥ 12:0, < 12:2022-07-01≥ 12L:0, < 12L:2022-07-012022-07-01
CVE-2022-20226 CVE-2022-20226: In finishDrawingWindow of WindowManagerService
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20201UNKNOWN≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20201 CVE-2022-20201: In getAppSize of InstalldNativeService
In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39691UNKNOWN≥ 10:0, < 10:2022-06-01≥ 11:0, < 11:2022-06-012022-06-01
CVE-2021-39691 CVE-2021-39691: In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input
In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39690UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39690 CVE-2021-39690: In setDisplayPadding of WallpaperManagerService
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39620UNKNOWN≥ 11:0, < 11:2022-01-01≥ 12:0, < 12:2022-01-012022-01-01
CVE-2021-39620 CVE-2021-39620: In ipcSetDataReference of Parcel
In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1028UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1028 CVE-2021-1028: In setClientStateLocked of SurfaceFlinger
In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1027UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1027 CVE-2021-1027: In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting
In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1029UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1029 CVE-2021-1029: In setClientStateLocked of SurfaceFlinger
In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0919UNKNOWN≥ 10:0, < 10:2021-11-01≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0919 CVE-2021-0919: In getService of IServiceManager
In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0684UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0684 CVE-2021-0684: In TouchInputMapper::sync of TouchInputMapper
In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0394UNKNOWN≥ 11:0, < 11:2021-03-012021-03-01
CVE-2021-0394 CVE-2021-0394: In android_os_Parcel_readString8 of android_os_Parcel
In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv