Platform Frameworks Native vulnerabilities

50 known vulnerabilities affecting platform/frameworks_native.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50

Vulnerabilities

Page 3 of 3
CVE-2021-0332UNKNOWN≥ 10:0, < 10:2021-02-01≥ 11:0, < 11:2021-02-012021-02-01
CVE-2021-0332 CVE-2021-0332: In bootFinished of SurfaceFlinger In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0310UNKNOWN≥ 11:0, < 11:2021-01-012021-01-01
CVE-2021-0310 CVE-2021-0310: In LazyServiceRegistrar of LazyServiceRegistrar In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0318UNKNOWN≥ 8.1:0, < 8.1:2021-01-01≥ 9:0, < 9:2021-01-01+2 more2021-01-01
CVE-2021-0318 CVE-2021-0318: In appendEventsToCacheLocked of SensorEventConnection In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0464UNKNOWN≥ 10:0, < 10:2020-12-012020-12-01
CVE-2020-0464 CVE-2020-0464: In resolv_cache_lookup of res_cache In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0438UNKNOWN≥ 11-next:0, < 11-next:2020-11-01≥ 10:0, < 10:2020-11-01+1 more2020-11-01
CVE-2020-0438 CVE-2020-0438: In the AIBinder_Class constructor of ibinder In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2019-2194UNKNOWN≥ 9:0, < 9:2020-10-012020-10-01
CVE-2019-2194 CVE-2019-2194: In SurfaceFlinger::createLayer of SurfaceFlinger In SurfaceFlinger::createLayer of SurfaceFlinger.cpp, there is a possible arbitrary code execution due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0420UNKNOWN≥ 11:0, < 11:2020-10-012020-10-01
CVE-2020-0420 CVE-2020-0420: In setUpdatableDriverPath of GpuService In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0382UNKNOWN≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0382 CVE-2020-0382: In RunInternal of dumpstate In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0392UNKNOWN≥ 9:0, < 9:2020-09-01≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0392 CVE-2020-0392: In getLayerDebugInfo of SurfaceFlinger In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0226UNKNOWN≥ 10:0, < 10:2020-07-012020-07-01
CVE-2020-0226 CVE-2020-0226: In createWithSurfaceParent of Client In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv