Vulnerability index

Browse CVEs

134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2022-20441 In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to loc… Android Mitigation only Fix from $1,9502022-11-08 HIGH 7.8 CVE-2022-20452 In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to lo… Android Mitigation only Fix from $1,9502022-11-08 MEDIUM 5.5 CVE-2022-20448 In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could… Android Mitigation only Fix from $1,6002022-11-08 HIGH 7.8 CVE-2022-20435 There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission… Android Mitigation only Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-20436 There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege… Android Mitigation only Fix from $1,9502022-10-11 MEDIUM 5.5 CVE-2022-20272 In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could l… Android Mitigation only Fix from $1,6002022-08-12 HIGH 7.8 CVE-2022-20246 In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check… Android Mitigation only Fix from $1,9502022-08-11 MEDIUM 5.5 CVE-2022-30758 Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with pr… Android Mitigation only Fix from $1,6002022-07-12 HIGH 7.8 CVE-2021-39794 In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a m… Android Mitigation only Fix from $1,9502022-04-12 HIGH 7.8 CVE-2021-39780 In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could l… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 5.5 CVE-2021-39769 In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. Thi… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39770 In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disc… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39779 In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call stat… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39747 In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local in… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39748 In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local in… Android Mitigation only Fix from $1,6002022-03-30 HIGH 7.8 CVE-2021-1000 In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-1033 In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could le… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 5.5 CVE-2021-22571 A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded i… Sa360 Webquery To Bigquery Exporter 1.0.3+ Fix from $1,6002022-03-18 HIGH 7.8 CVE-2021-39694 In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. T… Android Mitigation only Fix from $1,9502022-03-16 HIGH 7.8 CVE-2022-25815 PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action wi… Android Mitigation only Fix from $1,9502022-03-10 HIGH 7.8 CVE-2022-25814 PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized ac… Android Mitigation only Fix from $1,9502022-03-10 MEDIUM 5.5 CVE-2022-25327 The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other u… Fscrypt 0.3.3+ Fix from $1,6002022-02-25 CRITICAL 9.8 CVE-2021-39658 ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions o… Android Mitigation only Fix from $2,3002022-02-11 CRITICAL 9.1 CVE-2021-39635 ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No ph… Android Mitigation only Fix from $2,3002022-02-11 MEDIUM 5.5 CVE-2021-0979 In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests… Android Patch available Fix from $1,6002021-12-15 HIGH 7.8 CVE-2021-0486 In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead… Android Patch available Fix from $1,9502021-07-14 HIGH 7.3 CVE-2021-0441 In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege w… Android Patch available Fix from $1,9502021-07-14 HIGH 8.8 CVE-2021-22538 A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker wh… Exposure Notifications Verification Server 0.23.1+ Fix from $1,9502021-03-31 MEDIUM 5.5 CVE-2021-0381 In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to … Android Patch available Fix from $1,6002021-03-10 HIGH 7.8 CVE-2020-0486 In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local … Android Patch available Fix from $1,9502020-12-15