Vulnerability index

Browse CVEs

161 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Android HIGH 7.8
CVE-2024-40662

In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation …

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-34741

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while…

Patch available
Fix from $1,950 2024-08-15
Android HIGH 7.8
CVE-2024-34743

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to loca…

Patch available
Fix from $1,950 2024-08-15
Android HIGH 7.8
CVE-2024-31334

In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead …

Mitigation only
Fix from $1,950 2024-07-09
Android HIGH 7.0
CVE-2024-34725

In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalat…

Mitigation only
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31318

In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. …

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31320

In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31322

In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaining Accessi…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31323

In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31325

In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to local escalati…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-23711

In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to …

Mitigation only
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31311

In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escal…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31313

In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2023-21113

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2023-21114

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit…

Patch available
Fix from $1,950 2024-07-09
Android MEDIUM 6.1
CVE-2024-32918

Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps

Mitigation only
Fix from $1,600 2024-06-13
Android HIGH 7.8
CVE-2024-32906

In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional …

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.0
CVE-2024-32899

In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to l…

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-29784

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-23713

In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input …

Patch available
Fix from $1,950 2024-05-07
Android HIGH 7.8
CVE-2024-0024

In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation.…

Patch available
Fix from $1,950 2024-05-07
Android HIGH 7.8
CVE-2024-23710

In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app du…

Patch available
Fix from $1,950 2024-05-07
Android MEDIUM 6.7
CVE-2024-20021

In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege…

Mitigation only
Fix from $1,600 2024-05-06
Android HIGH 7.8
CVE-2024-29741

In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privileg…

Mitigation only
Fix from $1,950 2024-04-05
Android CRITICAL 9.1
CVE-2024-27207

Exported broadcast receivers allowing malicious apps to bypass broadcast protection.

No fix yet
Fix from $2,300 2024-03-11
Android HIGH 7.8
CVE-2024-27210

In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-27222

In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_P…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-27224

In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-27233

In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-22008

In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2024-03-11