Vulnerability index

Browse CVEs

134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 5.1 CVE-2025-22425 In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of pri… Android Patch available Fix from $1,6002025-09-04 CRITICAL 9.8 CVE-2025-6179 Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensi… Chrome Os Mitigation only Fix from $2,3002025-06-16 HIGH 7.8 CVE-2024-49732 In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permi… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-49735 In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of… Android No fix yet Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-49737 In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a lo… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-49744 In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deseri… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.0 CVE-2024-49724 In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race cond… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-34730 In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-43765 In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation o… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2023-40132 In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permiss… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2018-9401 In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalatio… Android Mitigation only Fix from $1,9502025-01-18 HIGH 7.8 CVE-2018-9434 In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of pri… Android Patch available Fix from $1,9502025-01-17 HIGH 7.8 CVE-2024-11624 there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional exec… Android Mitigation only Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-53835 there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution priv… Android No fix yet Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-53840 there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution priv… Android No fix yet Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-53841 In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privil… Android Mitigation only Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-43769 In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logi… Android Mitigation only Fix from $1,9502025-01-03 HIGH 7.8 CVE-2018-9431 In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of priv… Android Patch available Fix from $1,9502024-12-02 CRITICAL 9.8 CVE-2018-9467 In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security deci… Android Mitigation only Fix from $2,3002024-11-20 HIGH 7.8 CVE-2018-9432 In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to … Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.3 CVE-2018-9369 In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.8 CVE-2023-21270 In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to … Android Patch available Fix from $1,9502024-11-19 HIGH 7.8 CVE-2017-13310 In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local e… Android Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2017-13312 In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escal… Android Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2017-13314 In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul… Android Patch available Fix from $1,9502024-11-15 MEDIUM 6.7 CVE-2017-13311 In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to l… Android Mitigation only Fix from $1,6002024-11-15 HIGH 7.8 CVE-2024-43085 In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic … Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43089 In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc… Android Patch available Fix from $1,9502024-11-13 MEDIUM 5.5 CVE-2024-43086 In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused… Android Patch available Fix from $1,6002024-11-13 HIGH 7.8 CVE-2024-40660 In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This c… Android Patch available Fix from $1,9502024-11-13