Vulnerability index

Browse CVEs

134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Android HIGH 7.8
CVE-2022-20441

In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to loc…

Mitigation only
Fix from $1,950 2022-11-08
Android HIGH 7.8
CVE-2022-20452

In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to lo…

Mitigation only
Fix from $1,950 2022-11-08
Android MEDIUM 5.5
CVE-2022-20448

In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could…

Mitigation only
Fix from $1,600 2022-11-08
Android HIGH 7.8
CVE-2022-20435

There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission…

Mitigation only
Fix from $1,950 2022-10-11
Android HIGH 7.8
CVE-2022-20436

There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege…

Mitigation only
Fix from $1,950 2022-10-11
Android MEDIUM 5.5
CVE-2022-20272

In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could l…

Mitigation only
Fix from $1,600 2022-08-12
Android HIGH 7.8
CVE-2022-20246

In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check…

Mitigation only
Fix from $1,950 2022-08-11
Android MEDIUM 5.5
CVE-2022-30758

Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with pr…

Mitigation only
Fix from $1,600 2022-07-12
Android HIGH 7.8
CVE-2021-39794

In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a m…

Mitigation only
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-39780

In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could l…

Mitigation only
Fix from $1,950 2022-03-30
Android MEDIUM 5.5
CVE-2021-39769

In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. Thi…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39770

In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disc…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39779

In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call stat…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39747

In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local in…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39748

In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local in…

Mitigation only
Fix from $1,600 2022-03-30
Android HIGH 7.8
CVE-2021-1000

In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-1033

In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could le…

Mitigation only
Fix from $1,950 2022-03-30
Sa360 Webquery To Bigquery Exporter MEDIUM 5.5
CVE-2021-22571

A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded i…

Fix: 1.0.3+
Fix from $1,600 2022-03-18
Android HIGH 7.8
CVE-2021-39694

In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. T…

Mitigation only
Fix from $1,950 2022-03-16
Android HIGH 7.8
CVE-2022-25815

PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action wi…

Mitigation only
Fix from $1,950 2022-03-10
Android HIGH 7.8
CVE-2022-25814

PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized ac…

Mitigation only
Fix from $1,950 2022-03-10
Fscrypt MEDIUM 5.5
CVE-2022-25327

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other u…

Fix: 0.3.3+
Fix from $1,600 2022-02-25
Android CRITICAL 9.8
CVE-2021-39658

ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions o…

Mitigation only
Fix from $2,300 2022-02-11
Android CRITICAL 9.1
CVE-2021-39635

ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No ph…

Mitigation only
Fix from $2,300 2022-02-11
Android MEDIUM 5.5
CVE-2021-0979

In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests…

Patch available
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-0486

In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead…

Patch available
Fix from $1,950 2021-07-14
Android HIGH 7.3
CVE-2021-0441

In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege w…

Patch available
Fix from $1,950 2021-07-14
Exposure Notifications Verification Server HIGH 8.8
CVE-2021-22538

A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker wh…

Fix: 0.23.1+
Fix from $1,950 2021-03-31
Android MEDIUM 5.5
CVE-2021-0381

In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to …

Patch available
Fix from $1,600 2021-03-10
Android HIGH 7.8
CVE-2020-0486

In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local …

Patch available
Fix from $1,950 2020-12-15