Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 7.8 CVE-2025-48535 In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywh… Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-32312 In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next… Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2018-9474 In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to… Android Patch available Fix from $1,9502024-11-20 HIGH 7.5 CVE-2024-10382 There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction… Androidx.car.app after 1.4.0 Fix from $1,9502024-11-20 HIGH 7.8 CVE-2024-43080 In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esc… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-8375 There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C+… Reverb 2024-08-05+ Fix from $1,9502024-09-19 HIGH 7.8 CVE-2024-31317 In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe des… Android Patch available Fix from $1,9502024-07-09 MEDIUM 5.5 CVE-2024-0047 In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to … Android Patch available Fix from $1,6002024-03-11 MEDIUM 5.5 CVE-2023-40121 In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local informatio… Android Patch available Fix from $1,6002023-10-27 HIGH 7.8 CVE-2023-35669 In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deseriali… Android Patch available Fix from $1,9502023-09-11 MEDIUM 6.7 CVE-2023-21209 In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of … Android Mitigation only Fix from $1,6002023-06-28 MEDIUM 5.5 CVE-2023-21205 In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local inform… Android Mitigation only Fix from $1,6002023-06-28 HIGH 7.8 CVE-2023-21124 In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege… Android Patch available Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-20944 In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local esca… Android Patch available Fix from $1,9502023-02-28 HIGH 7.8 CVE-2022-32601 In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with no additio… Android Mitigation only Fix from $1,9502022-11-08 HIGH 7.8 CVE-2022-26471 In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no a… Android Mitigation only Fix from $1,9502022-10-07 HIGH 7.8 CVE-2022-26472 In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additio… Android Mitigation only Fix from $1,9502022-10-07 MEDIUM 5.0 CVE-2022-20195 In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This could lead to local denial o… Android Mitigation only Fix from $1,6002022-06-15 HIGH 7.8 CVE-2021-0970 In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalat… Android Patch available Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-0685 In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This c… Android Patch available Fix from $1,9502021-10-06 HIGH 8.8 CVE-2021-37678 TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be tricked to perform arbitrary … Tensorflow 2.3.4 / 2.4.3+ Fix from $1,9502021-08-12 MEDIUM 5.5 CVE-2020-0132 In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local … Android Patch available Fix from $1,6002020-06-11 HIGH 7.8 CVE-2020-0082 In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead … Android Mitigation only Fix from $1,9502020-04-17 CRITICAL 9.8 CVE-2019-9365 In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional… Android Mitigation only Fix from $2,3002019-09-27 MEDIUM 5.5 CVE-2019-9373 In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of servic… Android Mitigation only Fix from $1,6002019-09-27 HIGH 8.8 CVE-2018-6162 Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via … Chrome 68.0.3440.75+ Fix from $1,9502019-01-09 HIGH 7.8 CVE-2017-13286 In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a l… Android Mitigation only Fix from $1,9502018-04-04 HIGH 7.8 CVE-2017-0806 An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0… Android Patch available Fix from $1,9502017-10-04 HIGH 7.5 CVE-2010-4574 The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not… Chrome 8.0.552.224 / 8.0.552.343+ Fix from $1,9502010-12-22 HIGH 9.3 CVE-2010-3258 The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attac… Chrome 6.0.472.53+ Fix from $1,9502010-09-07