cbcvebase.

Platform Frameworks Native vulnerabilities

50 known vulnerabilities affecting platform/frameworks_native.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50

Vulnerabilities

Page 3 of 3
CVE-2022-20357P4UNKNOWN≥ 12:0, < 12:2022-08-01≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20357 CVE-2022-20357: In writeToParcel of SurfaceControl In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0464P4UNKNOWN≥ 10:0, < 10:2020-12-012020-12-01
CVE-2020-0464 CVE-2020-0464: In resolv_cache_lookup of res_cache In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39690P4UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39690 CVE-2021-39690: In setDisplayPadding of WallpaperManagerService In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21031P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21031 CVE-2023-21031: In setPowerMode of HWC2 In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0919P4UNKNOWN≥ 10:0, < 10:2021-11-01≥ 11:0, < 11:2021-11-012021-11-01
CVE-2021-0919 CVE-2021-0919: In getService of IServiceManager In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lead to local denial of service making the lockscreen unusable with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20226P4UNKNOWN≥ 12:0, < 12:2022-07-01≥ 12L:0, < 12L:2022-07-012022-07-01
CVE-2022-20226 CVE-2022-20226: In finishDrawingWindow of WindowManagerService In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0382P4UNKNOWN≥ 10:0, < 10:2020-09-012020-09-01
CVE-2020-0382 CVE-2020-0382: In RunInternal of dumpstate In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49746UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+4 more2025-02-01
CVE-2024-49746 CVE-2024-49746: In multiple functions of Parcel In multiple functions of Parcel.cpp, there is a possible way to manipulate file descriptors and escalate privileges due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39617UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+2 more2023-05-01
CVE-2021-39617 CVE-2021-39617: In multiple buttons of grant_permissions In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20444UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+1 more2023-05-01
CVE-2022-20444 CVE-2022-20444: In several functions of inputDispatcher In several functions of inputDispatcher.cpp, there is a possible way to make toasts clickable due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Native vulnerabilities | cvebase