Vulnerability index

Browse CVEs

134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Android MEDIUM 5.1
CVE-2025-22425

In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of pri…

Patch available
Fix from $1,600 2025-09-04
Chrome Os CRITICAL 9.8
CVE-2025-6179

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensi…

Mitigation only
Fix from $2,300 2025-06-16
Android HIGH 7.8
CVE-2024-49732

In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permi…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-49735

In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of…

No fix yet
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-49737

In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a lo…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-49744

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deseri…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.0
CVE-2024-49724

In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race cond…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-34730

In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-43765

In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2023-40132

In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permiss…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2018-9401

In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2025-01-18
Android HIGH 7.8
CVE-2018-9434

In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2025-01-17
Android HIGH 7.8
CVE-2024-11624

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional exec…

Mitigation only
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-53835

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution priv…

No fix yet
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-53840

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution priv…

No fix yet
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-53841

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privil…

Mitigation only
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2024-43769

In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logi…

Mitigation only
Fix from $1,950 2025-01-03
Android HIGH 7.8
CVE-2018-9431

In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of priv…

Patch available
Fix from $1,950 2024-12-02
Android CRITICAL 9.8
CVE-2018-9467

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security deci…

Mitigation only
Fix from $2,300 2024-11-20
Android HIGH 7.8
CVE-2018-9432

In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to …

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.3
CVE-2018-9369

In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2023-21270

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to …

Patch available
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2017-13310

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local e…

Mitigation only
Fix from $1,950 2024-11-15
Android HIGH 7.8
CVE-2017-13312

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escal…

Mitigation only
Fix from $1,950 2024-11-15
Android HIGH 7.8
CVE-2017-13314

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul…

Patch available
Fix from $1,950 2024-11-15
Android MEDIUM 6.7
CVE-2017-13311

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to l…

Mitigation only
Fix from $1,600 2024-11-15
Android HIGH 7.8
CVE-2024-43085

In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic …

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43089

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc…

Patch available
Fix from $1,950 2024-11-13
Android MEDIUM 5.5
CVE-2024-43086

In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused…

Patch available
Fix from $1,600 2024-11-13
Android HIGH 7.8
CVE-2024-40660

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This c…

Patch available
Fix from $1,950 2024-11-13