cbcvebase.

Platform Packages Apps Settings vulnerabilities

138 known vulnerabilities affecting platform/packages_apps_settings.

Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138

Vulnerabilities

Page 3 of 7
CVE-2023-21174P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21174 CVE-2023-21174: In isPageSearchEnabled of BillingCycleSettings In isPageSearchEnabled of BillingCycleSettings.java, there is a possible way for the guest user to change data limits due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20975P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20975 CVE-2023-20975: In getAvailabilityStatus of EnableContentCapturePreferenceController In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21107P3UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21107 CVE-2023-21107: In retrieveAppEntry of NotificationAccessDetails In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35667P3UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35667 CVE-2023-35667: In updateList of NotificationAccessSettings In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0108P3UNKNOWN≥ 8.1:0, < 8.1:2020-08-01≥ 9:0, < 9:2020-08-01+1 more2020-08-01
CVE-2020-0108 CVE-2020-0108: In postNotification of ServiceRecord In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0394P3UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0394 CVE-2020-0394: In onCreate of BluetoothPairingDialog In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0336P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0336 CVE-2021-0336: In onReceive of BluetoothPermissionRequest In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20223P3UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-01+2 more2022-07-01
CVE-2022-20223 CVE-2022-20223: In assertSafeToStartCustomActivity of AppRestrictionsFragment In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39626P3UNKNOWN≥ 9:0, < 9:2022-01-01≥ 10:0, < 10:2022-01-01+2 more2022-01-01
CVE-2021-39626 CVE-2021-39626: In onAttach of ConnectedDeviceDashboardFragment In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20506P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20506 CVE-2022-20506: In onCreate of WifiDialogActivity In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20522P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20522 CVE-2022-20522: In getSlice of ProviderModelSlice In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20144P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-012022-12-01
CVE-2022-20144 CVE-2022-20144: In cropPhoto of EditUserPhotoController In cropPhoto of EditUserPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0602P3UNKNOWN≥ 10:0, < 10:2021-07-01≥ 11:0, < 11:2021-07-012021-07-01
CVE-2021-0602 CVE-2021-0602: In onCreateOptionsMenu of WifiNetworkDetailsFragment In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi-Fi settings for all configured APs due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43080P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43080 CVE-2024-43080: In onReceive of AppRestrictionsFragment In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-43087P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43087 CVE-2024-43087: In getInstalledAccessibilityPreferences of AccessibilitySettings In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20348P3UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20348 CVE-2022-20348: In updateState of LocationServicesWifiScanningPreferenceController In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20194P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20194 CVE-2022-20194: In onCreate of ChooseLockGeneric In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21002P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21002 CVE-2023-21002: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21256P3UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 13:0, < 13:2023-07-012023-07-01
CVE-2023-21256 CVE-2023-21256: In SettingsHomepageActivity In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39807P3UNKNOWN≥ 10:0, < 10:2022-04-05≥ 11:0, < 11:2022-04-05+2 more2022-04-01
CVE-2021-39807 CVE-2021-39807: In handleNfcStateChanged of SecureNfcEnabler In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Packages Apps Settings vulnerabilities | cvebase