Platform Packages Apps Settings vulnerabilities
138 known vulnerabilities affecting platform/packages_apps_settings.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138
Vulnerabilities
Page 7 of 7
CVE-2021-0600UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0600 CVE-2021-0600: In onCreate of DeviceAdminAdd
In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0553UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0553 CVE-2021-0553: In onBindViewHolder of AppSwitchPreference
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0505UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0505 CVE-2021-0505: In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0523UNKNOWN≥ 10:0, < 10:2021-06-01≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0523 CVE-2021-0523: In onCreate of WifiScanModeActivity
In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0506UNKNOWN≥ 8.1:0, < 8.1:2021-06-01≥ 9:0, < 9:2021-06-01+2 more2021-06-01
CVE-2021-0506 CVE-2021-0506: In ActivityPicker
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0552UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0552 CVE-2021-0552: In getEndItemSliceAction of MediaOutputSlice
In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0481UNKNOWN≥ 8.1:0, < 8.1:2021-05-01≥ 9:0, < 9:2021-05-01+2 more2021-05-01
CVE-2021-0481 CVE-2021-0481: In onActivityResult of EditUserPhotoController
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0336UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0336 CVE-2021-0336: In onReceive of BluetoothPermissionRequest
In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0333UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0333 CVE-2021-0333: In onCreate of BluetoothPermissionActivity
In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0305UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0305 CVE-2021-0305: In PackageInstaller, there is a possible tapjacking attack due to an insecure default value
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0331UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0331 CVE-2021-0331: In onCreate of NotificationAccessConfirmationActivity
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0459UNKNOWN≥ 8.0:0, < 8.0:2020-12-01≥ 8.1:0, < 8.1:2020-12-01+2 more2020-12-01
CVE-2020-0459 CVE-2020-0459: In sendConfiguredNetworkChangedBroadcast of WifiConfigManager
In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0416UNKNOWN≥ 8.0:0, < 8.0:2020-10-01≥ 8.1:0, < 8.1:2020-10-01+2 more2020-10-01
CVE-2020-0416 CVE-2020-0416: In multiple settings screens, there are possible tapjacking attacks due to an insecure default value
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0396UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0396 CVE-2020-0396: In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent
In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0394UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0394 CVE-2020-0394: In onCreate of BluetoothPairingDialog
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0386UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0386 CVE-2020-0386: In onCreate of RequestPermissionActivity
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0238UNKNOWN≥ 8.0:0, < 8.0:2020-08-01≥ 8.1:0, < 8.1:2020-08-01+2 more2020-08-01
CVE-2020-0238 CVE-2020-0238: In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition
In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0108UNKNOWN≥ 8.1:0, < 8.1:2020-08-01≥ 9:0, < 9:2020-08-01+1 more2020-08-01
CVE-2020-0108 CVE-2020-0108: In postNotification of ServiceRecord
In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
← Previous7 / 7