Vulnerability index

Browse CVEs

134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2024-40661 In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43081 In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This c… Android Patch available Fix from $1,9502024-11-13 HIGH 8.8 CVE-2024-47014 Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292. Android Mitigation only Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-47012 In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to l… Android Mitigation only Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-47013 In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation… Android Mitigation only Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-47016 there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execut… Android No fix yet Fix from $1,9502024-10-25 HIGH 7.5 CVE-2024-44100 Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545. Android 2024-10-05+ Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-9858 There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser… Migrate To Containers 1.2.3+ Fix from $1,9502024-10-16 HIGH 7.8 CVE-2024-40654 In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40655 In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background d… Android Patch available Fix from $1,9502024-09-11 MEDIUM 5.5 CVE-2024-31312 In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposi… Android Patch available Fix from $1,6002024-07-09 HIGH 8.2 CVE-2024-20005 In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executio… Android Mitigation only Fix from $1,9502024-03-04 HIGH 7.8 CVE-2024-0034 In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to … Android Patch available Fix from $1,9502024-02-16 MEDIUM 5.5 CVE-2023-40076 In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This … Android Patch available Fix from $1,6002023-12-04 CRITICAL 9.8 CVE-2023-21216 In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local e… Android Mitigation only Fix from $2,3002023-12-04 HIGH 7.8 CVE-2023-21187 In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to … Android Mitigation only Fix from $1,9502023-06-28 HIGH 7.8 CVE-2023-21175 In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This … Android Mitigation only Fix from $1,9502023-06-28 HIGH 7.8 CVE-2023-21138 In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to loc… Android Patch available Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-21139 In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escala… Android Patch available Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-21121 In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input … Android Mitigation only Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-21126 In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. Th… Android Patch available Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-21128 In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This co… Android Patch available Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-21129 In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background… Android Mitigation only Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-21107 In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local escalation of privilege across u… Android Patch available Fix from $1,9502023-05-15 MEDIUM 5.5 CVE-2023-21104 In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution p… Android Patch available Fix from $1,6002023-05-15 HIGH 7.8 CVE-2022-20456 In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead… Android Mitigation only Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-20611 In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. Th… Android Patch available Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-20474 In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead… Android Patch available Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-20475 In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This… Android Patch available Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-20495 In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in … Android Patch available Fix from $1,9502022-12-13