Vulnerability index

Browse CVEs

161 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2024-40662 In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation … Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-34741 In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while… Android Patch available Fix from $1,9502024-08-15 HIGH 7.8 CVE-2024-34743 In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to loca… Android Patch available Fix from $1,9502024-08-15 HIGH 7.8 CVE-2024-31334 In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead … Android Mitigation only Fix from $1,9502024-07-09 HIGH 7.0 CVE-2024-34725 In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalat… Android Mitigation only Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31318 In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. … Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31320 In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31322 In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaining Accessi… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31323 In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31325 In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to local escalati… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-23711 In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to … Android Mitigation only Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31311 In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escal… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31313 In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2023-21113 In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2023-21114 In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit… Android Patch available Fix from $1,9502024-07-09 MEDIUM 6.1 CVE-2024-32918 Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps Android Mitigation only Fix from $1,6002024-06-13 HIGH 7.8 CVE-2024-32906 In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional … Android Mitigation only Fix from $1,9502024-06-13 HIGH 7.0 CVE-2024-32899 In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to l… Android Mitigation only Fix from $1,9502024-06-13 HIGH 7.8 CVE-2024-29784 In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of… Android Mitigation only Fix from $1,9502024-06-13 HIGH 7.8 CVE-2024-23713 In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input … Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-0024 In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation.… Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-23710 In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app du… Android Patch available Fix from $1,9502024-05-07 MEDIUM 6.7 CVE-2024-20021 In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege… Android Mitigation only Fix from $1,6002024-05-06 HIGH 7.8 CVE-2024-29741 In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privileg… Android Mitigation only Fix from $1,9502024-04-05 CRITICAL 9.1 CVE-2024-27207 Exported broadcast receivers allowing malicious apps to bypass broadcast protection. Android No fix yet Fix from $2,3002024-03-11 HIGH 7.8 CVE-2024-27210 In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wit… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-27222 In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_P… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-27224 In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-27233 In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-22008 In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr… Android Mitigation only Fix from $1,9502024-03-11