Vulnerability index

Browse CVEs

161 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2022-20360 In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the g… Android Patch available Fix from $1,9502022-08-10 CRITICAL 9.8 CVE-2022-20239 remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be contr… Android Mitigation only Fix from $2,3002022-08-10 HIGH 8.8 CVE-2022-20347 In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escal… Android Patch available Fix from $1,9502022-08-10 HIGH 7.8 CVE-2022-20114 In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a pe… Android Patch available Fix from $1,9502022-05-10 MEDIUM 5.5 CVE-2022-20112 In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a per… Android Mitigation only Fix from $1,6002022-05-10 HIGH 7.8 CVE-2021-39797 In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local … Android Mitigation only Fix from $1,9502022-04-12 HIGH 7.8 CVE-2021-39807 In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. Th… Android Patch available Fix from $1,9502022-04-12 HIGH 8.8 CVE-2021-39772 In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This could lead to local escalation … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39782 In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalati… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39783 In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39784 In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local e… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2022-24931 Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbi… Android Mitigation only Fix from $1,9502022-03-10 MEDIUM 5.5 CVE-2022-20051 In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service… Android Mitigation only Fix from $1,6002022-03-10 MEDIUM 5.5 CVE-2022-22263 Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity. Android Mitigation only Fix from $1,6002022-01-10 MEDIUM 5.5 CVE-2021-25502 A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value w… Android Mitigation only Fix from $1,6002021-11-05 MEDIUM 6.7 CVE-2021-0691 In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-… Android Patch available Fix from $1,6002021-10-06 HIGH 7.8 CVE-2021-25428 Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permi… Android Mitigation only Fix from $1,9502021-07-08 HIGH 7.8 CVE-2021-25365 An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd. Android Mitigation only Fix from $1,9502021-04-09 MEDIUM 6.1 CVE-2021-25362 An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files. Android Mitigation only Fix from $1,6002021-04-09 MEDIUM 6.1 CVE-2021-25363 An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete … Android Mitigation only Fix from $1,6002021-04-09 HIGH 7.8 CVE-2021-0327 In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lea… Android Patch available Fix from $1,9502021-02-10 HIGH 7.8 CVE-2021-0306 In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an a… Android Mitigation only Fix from $1,9502021-01-11 MEDIUM 6.7 CVE-2020-0403 In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation… Android Mitigation only Fix from $1,6002020-09-17 MEDIUM 5.5 CVE-2020-0404 In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalati… Android Mitigation only Fix from $1,6002020-09-17 HIGH 7.8 CVE-2020-0074 In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a… Android Patch available Fix from $1,9502020-09-17 MEDIUM 6.5 CVE-2019-13738 Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted… Chrome 79.0.3945.79+ Fix from $1,6002019-12-10 HIGH 8.8 CVE-2019-2225 When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the user, and that device may be ab… Android Patch available Fix from $1,9502019-12-06 HIGH 7.8 CVE-2019-13702 Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation … Chrome 78.0.3904.70+ Fix from $1,9502019-11-25 HIGH 7.8 CVE-2019-2193 In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lea… Android Mitigation only Fix from $1,9502019-11-13 HIGH 7.8 CVE-2018-9425 In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of pri… Android Mitigation only Fix from $1,9502019-09-27