cbcvebase.

Platform Packages Apps Settings vulnerabilities

138 known vulnerabilities affecting platform/packages_apps_settings.

Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138

Vulnerabilities

Page 5 of 7
CVE-2021-39707P3UNKNOWN≥ 10:0, < 10:2022-03-01≥ 11:0, < 11:2022-03-01+2 more2022-03-01
CVE-2021-39707 CVE-2021-39707: In onReceive of AppRestrictionsFragment In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0505P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0505 CVE-2021-0505: In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40654P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40654 CVE-2024-40654: In multiple locations, there is a possible permission bypass due to a confused deputy In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0600P3UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0600 CVE-2021-0600: In onCreate of DeviceAdminAdd In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39702P3UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39702 CVE-2021-39702: In onCreate of RequestManageCredentials In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0586P3UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0586 CVE-2021-0586: In onCreate of DevicePickerFragment In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0593P3UNKNOWN≥ 8.1:0, < 8.1:2021-08-01≥ 9:0, < 9:2021-08-01+2 more2021-08-01
CVE-2021-0593 CVE-2021-0593: In sendDevicePickedIntent of DevicePickerFragment In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileged broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0333P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0333 CVE-2021-0333: In onCreate of BluetoothPermissionActivity In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20137P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12:0, < 12:2022-06-01+1 more2022-06-01
CVE-2022-20137 CVE-2022-20137: In onCreateContextMenu of NetworkProviderSettings In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20976P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20976 CVE-2023-20976: In getConfirmationMessage of DefaultAutofillPicker In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39669P3UNKNOWN≥ 11:0, < 11:2022-02-01≥ 12:0, < 12:2022-02-012022-02-01
CVE-2021-39669 CVE-2021-39669: In onCreate of InstallCaCertificateWarning In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0591P3UNKNOWN≥ 8.1:0, < 8.1:2021-08-01≥ 9:0, < 9:2021-08-01+2 more2021-08-01
CVE-2021-0591 CVE-2021-0591: In sendReplyIntentToReceiver of BluetoothPermissionActivity In sendReplyIntentToReceiver of BluetoothPermissionActivity.java, there is a possible way to invoke privileged broadcast receivers due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0506P3UNKNOWN≥ 8.1:0, < 8.1:2021-06-01≥ 9:0, < 9:2021-06-01+2 more2021-06-01
CVE-2021-0506 CVE-2021-0506: In ActivityPicker In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0331P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0331 CVE-2021-0331: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0553P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0553 CVE-2021-0553: In onBindViewHolder of AppSwitchPreference In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0769P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0769 CVE-2021-0769: In onCreate of AllowBindAppWidgetActivity In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to unclear UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1019P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1019 CVE-2021-1019: In snoozeNotification of NotificationListenerService In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0434P4UNKNOWN≥ 9:0, < 9:2021-11-01≥ 10:0, < 10:2021-11-01+1 more2021-11-01
CVE-2021-0434 CVE-2021-0434: In onReceive of BluetoothPermissionRequest In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0523P4UNKNOWN≥ 10:0, < 10:2021-06-01≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0523 CVE-2021-0523: In onCreate of WifiScanModeActivity In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0238P4UNKNOWN≥ 8.0:0, < 8.0:2020-08-01≥ 8.1:0, < 8.1:2020-08-01+2 more2020-08-01
CVE-2020-0238 CVE-2020-0238: In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Packages Apps Settings vulnerabilities | cvebase