Vulnerability index

Browse CVEs

161 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Android HIGH 7.8
CVE-2022-20360

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the g…

Patch available
Fix from $1,950 2022-08-10
Android CRITICAL 9.8
CVE-2022-20239

remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be contr…

Mitigation only
Fix from $2,300 2022-08-10
Android HIGH 8.8
CVE-2022-20347

In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escal…

Patch available
Fix from $1,950 2022-08-10
Android HIGH 7.8
CVE-2022-20114

In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a pe…

Patch available
Fix from $1,950 2022-05-10
Android MEDIUM 5.5
CVE-2022-20112

In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a per…

Mitigation only
Fix from $1,600 2022-05-10
Android HIGH 7.8
CVE-2021-39797

In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local …

Mitigation only
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-39807

In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. Th…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 8.8
CVE-2021-39772

In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This could lead to local escalation …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39782

In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalati…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39783

In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39784

In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local e…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2022-24931

Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbi…

Mitigation only
Fix from $1,950 2022-03-10
Android MEDIUM 5.5
CVE-2022-20051

In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service…

Mitigation only
Fix from $1,600 2022-03-10
Android MEDIUM 5.5
CVE-2022-22263

Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.

Mitigation only
Fix from $1,600 2022-01-10
Android MEDIUM 5.5
CVE-2021-25502

A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value w…

Mitigation only
Fix from $1,600 2021-11-05
Android MEDIUM 6.7
CVE-2021-0691

In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-…

Patch available
Fix from $1,600 2021-10-06
Android HIGH 7.8
CVE-2021-25428

Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permi…

Mitigation only
Fix from $1,950 2021-07-08
Android HIGH 7.8
CVE-2021-25365

An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.

Mitigation only
Fix from $1,950 2021-04-09
Android MEDIUM 6.1
CVE-2021-25362

An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.

Mitigation only
Fix from $1,600 2021-04-09
Android MEDIUM 6.1
CVE-2021-25363

An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete …

Mitigation only
Fix from $1,600 2021-04-09
Android HIGH 7.8
CVE-2021-0327

In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lea…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0306

In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an a…

Mitigation only
Fix from $1,950 2021-01-11
Android MEDIUM 6.7
CVE-2020-0403

In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 5.5
CVE-2020-0404

In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalati…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 7.8
CVE-2020-0074

In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a…

Patch available
Fix from $1,950 2020-09-17
Chrome MEDIUM 6.5
CVE-2019-13738

Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Android HIGH 8.8
CVE-2019-2225

When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the user, and that device may be ab…

Patch available
Fix from $1,950 2019-12-06
Chrome HIGH 7.8
CVE-2019-13702

Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation …

Fix: 78.0.3904.70+
Fix from $1,950 2019-11-25
Android HIGH 7.8
CVE-2019-2193

In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lea…

Mitigation only
Fix from $1,950 2019-11-13
Android HIGH 7.8
CVE-2018-9425

In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of pri…

Mitigation only
Fix from $1,950 2019-09-27