Platform Frameworks Native vulnerabilities
50 known vulnerabilities affecting platform/frameworks_native.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50
Vulnerabilities
Page 3 of 3
CVE-2022-20357P4UNKNOWN≥ 12:0, < 12:2022-08-01≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20357 CVE-2022-20357: In writeToParcel of SurfaceControl
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0464P4UNKNOWN≥ 10:0, < 10:2020-12-012020-12-01
CVE-2020-0464 CVE-2020-0464: In resolv_cache_lookup of res_cache
In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39690P4UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39690 CVE-2021-39690: In setDisplayPadding of WallpaperManagerService
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21031P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21031 CVE-2023-21031: In setPowerMode of HWC2
In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0919P4UNKNOWN≥ 10:0, < 10:2021-11-01≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0919 CVE-2021-0919: In getService of IServiceManager
In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20226P4UNKNOWN≥ 12:0, < 12:2022-07-01≥ 12L:0, < 12L:2022-07-012022-07-01
CVE-2022-20226 CVE-2022-20226: In finishDrawingWindow of WindowManagerService
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0382P4UNKNOWN≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0382 CVE-2020-0382: In RunInternal of dumpstate
In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49746UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+4 more2025-02-01
CVE-2024-49746 CVE-2024-49746: In multiple functions of Parcel
In multiple functions of Parcel.cpp, there is a possible way to manipulate file descriptors and escalate privileges due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39617UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+2 more2023-05-01
CVE-2021-39617 CVE-2021-39617: In multiple buttons of grant_permissions
In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20444UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+1 more2023-05-01
CVE-2022-20444 CVE-2022-20444: In several functions of inputDispatcher
In several functions of inputDispatcher.cpp, there is a possible way to make toasts clickable due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
← Previous3 / 3