cbcvebase.

Platform Frameworks Native vulnerabilities

50 known vulnerabilities affecting platform/frameworks_native.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50

Vulnerabilities

Page 2 of 3
CVE-2020-0226P3UNKNOWN≥ 10:0, < 10:2020-07-012020-07-01
CVE-2020-0226 CVE-2020-0226: In createWithSurfaceParent of Client In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0392P3UNKNOWN≥ 9:0, < 9:2020-09-01≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0392 CVE-2020-0392: In getLayerDebugInfo of SurfaceFlinger In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0318P3UNKNOWN≥ 8.1:0, < 8.1:2021-01-01≥ 9:0, < 9:2021-01-01+2 more2021-01-01
CVE-2021-0318 CVE-2021-0318: In appendEventsToCacheLocked of SensorEventConnection In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0332P3UNKNOWN≥ 10:0, < 10:2021-02-01≥ 11:0, < 11:2021-02-012021-02-01
CVE-2021-0332 CVE-2021-0332: In bootFinished of SurfaceFlinger In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0310P3UNKNOWN≥ 11:0, < 11:2021-01-012021-01-01
CVE-2021-0310 CVE-2021-0310: In LazyServiceRegistrar of LazyServiceRegistrar In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0420P3UNKNOWN≥ 11:0, < 11:2020-10-012020-10-01
CVE-2020-0420 CVE-2020-0420: In setUpdatableDriverPath of GpuService In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1028P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1028 CVE-2021-1028: In setClientStateLocked of SurfaceFlinger In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1029P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1029 CVE-2021-1029: In setClientStateLocked of SurfaceFlinger In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21034P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21034 CVE-2023-21034: In multiple functions of SensorService In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39620P3UNKNOWN≥ 11:0, < 11:2022-01-01≥ 12:0, < 12:2022-01-012022-01-01
CVE-2021-39620 CVE-2021-39620: In ipcSetDataReference of Parcel In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0684P3UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0684 CVE-2021-0684: In TouchInputMapper::sync of TouchInputMapper In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48639P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48639 CVE-2025-48639: In DefaultTransitionHandler In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39691P3UNKNOWN≥ 10:0, < 10:2022-06-01≥ 11:0, < 11:2022-06-012022-06-01
CVE-2021-39691 CVE-2021-39691: In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-40131P4UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 12:0, < 12:2023-10-01+2 more2023-10-01
CVE-2023-40131 CVE-2023-40131: In GpuService of GpuService In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20344P4UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20344 CVE-2022-20344: In stealReceiveChannel of EventThread In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20554P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20554 CVE-2022-20554: In removeEventHubDevice of InputDevice In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20201P4UNKNOWN≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20201 CVE-2022-20201: In getAppSize of InstalldNativeService In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21171P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21171 CVE-2023-21171: In verifyInputEvent of InputDispatcher In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to side channel information disclosure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0394P4UNKNOWN≥ 11:0, < 11:2021-03-012021-03-01
CVE-2021-0394 CVE-2021-0394: In android_os_Parcel_readString8 of android_os_Parcel In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21118P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21118 CVE-2023-21118: In unflattenString8 of Sensor In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Native vulnerabilities | cvebase