cbcvebase.

Platform Packages Apps Settings vulnerabilities

138 known vulnerabilities affecting platform/packages_apps_settings.

Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138

Vulnerabilities

Page 4 of 7
CVE-2023-21024P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21024 CVE-2023-21024: In maybeFinish of FallbackHome In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21172P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21172 CVE-2023-21172: In multiple functions of WifiCallingSettings In multiple functions of WifiCallingSettings.java, there is a possible way to change calling preferences for the admin user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23707P3UNKNOWN≥ 14-next:0, < 14-next:2024-05-01≥ 14:0, < 14:2024-05-012024-05-01
CVE-2024-23707 CVE-2024-23707: In multiple locations, there is a possible permissions bypass due to improper input validation In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21135P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21135 CVE-2023-21135: In onCreate of NotificationAccessSettings In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20349P3UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20349 CVE-2022-20349: In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permissio In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21005P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21005 CVE-2023-21005: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21015P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21015 CVE-2023-21015: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21003P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21003 CVE-2023-21003: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21004P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21004 CVE-2023-21004: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21175P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21175 CVE-2023-21175: In onCreate of DataUsageSummary In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20957P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+2 more2023-03-01
CVE-2023-20957 CVE-2023-20957: In onAttach of SettingsPreferenceFragment In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20959P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20959 CVE-2023-20959: In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22427P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22427 CVE-2025-22427: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21001P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21001 CVE-2023-21001: In onContextItemSelected of NetworkProviderSettings In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21121P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+1 more2023-06-01
CVE-2023-21121 CVE-2023-21121: In onResume of AppManagementFragment In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40652P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40652 CVE-2024-40652: In onCreate of SettingsHomepageActivity In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0481P3UNKNOWN≥ 8.1:0, < 8.1:2021-05-01≥ 9:0, < 9:2021-05-01+2 more2021-05-01
CVE-2021-0481 CVE-2021-0481: In onActivityResult of EditUserPhotoController In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39706P3UNKNOWN≥ 10:0, < 10:2022-03-01≥ 11:0, < 11:2022-03-01+2 more2022-03-01
CVE-2021-39706 CVE-2021-39706: In onResume of CredentialStorage In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0305P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0305 CVE-2021-0305: In PackageInstaller, there is a possible tapjacking attack due to an insecure default value In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-0021P3UNKNOWN≥ 14-next:0, < 14-next:2024-01-01≥ 13:0, < 13:2024-01-01+1 more2024-01-01
CVE-2024-0021 CVE-2024-0021: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
Platform Packages Apps Settings vulnerabilities | cvebase