Vulnerability index

Browse CVEs

66 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Chrome MEDIUM 6.5
CVE-2026-10997

Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Android HIGH 7.5
CVE-2025-0093

In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to re…

Mitigation only
Fix from $1,950 2025-08-26
Chrome CRITICAL 9.6
CVE-2025-4609

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to poten…

Fix: 136.0.7103.113+
Fix from $2,300 2025-08-22
Android MEDIUM 5.0
CVE-2024-0019

In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a miss…

Patch available
Fix from $1,600 2024-02-16
Android MEDIUM 5.5
CVE-2023-21142

In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclos…

Patch available
Fix from $1,600 2023-06-15
Android MEDIUM 5.5
CVE-2023-20923

In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to a permissions bypass. This c…

Mitigation only
Fix from $1,600 2023-01-26
Android HIGH 7.8
CVE-2022-20398

In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could le…

Patch available
Fix from $1,950 2022-09-13
Android MEDIUM 5.5
CVE-2022-20399

In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to loc…

Patch available
Fix from $1,600 2022-09-13
Android HIGH 7.5
CVE-2022-20234

In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName'…

Patch available
Fix from $1,950 2022-07-13
Android HIGH 7.8
CVE-2022-20218

In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could le…

Mitigation only
Fix from $1,950 2022-07-13
Android HIGH 7.8
CVE-2022-33695

Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

Mitigation only
Fix from $1,950 2022-07-12
Fuchsia MEDIUM 5.5
CVE-2022-0247

An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO…

Fix: 2022-01-03+
Fix from $1,600 2022-02-25
Fuchsia CRITICAL 9.8
CVE-2021-22566

An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged …

Patch available
Fix from $2,300 2022-01-18
Android HIGH 7.8
CVE-2021-39621

In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could le…

Mitigation only
Fix from $1,950 2022-01-14
Android HIGH 7.8
CVE-2021-39627

In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could le…

Mitigation only
Fix from $1,950 2022-01-14
Android MEDIUM 6.7
CVE-2021-0904

In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System…

Mitigation only
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-0692

In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to loca…

Patch available
Fix from $1,950 2021-10-06
Chrome HIGH 7.8
CVE-2021-30577

Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation …

Fix: 92.0.4515.107+
Fix from $1,950 2021-08-03
Android HIGH 7.8
CVE-2020-0417

In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to…

Patch available
Fix from $1,950 2021-07-14
Android MEDIUM 5.5
CVE-2021-0552

In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local inf…

Mitigation only
Fix from $1,600 2021-06-22
Android HIGH 7.8
CVE-2021-0570

In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead …

Mitigation only
Fix from $1,950 2021-06-22
Android MEDIUM 5.5
CVE-2021-0572

In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local infor…

Mitigation only
Fix from $1,600 2021-06-22
Android HIGH 7.8
CVE-2021-0477

In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could …

Patch available
Fix from $1,950 2021-06-11
Android MEDIUM 5.5
CVE-2021-25393

Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system ui…

No fix yet
Fix from $1,600 2021-06-11
Android HIGH 7.8
CVE-2021-0372

In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local…

Mitigation only
Fix from $1,950 2021-03-10
Chrome MEDIUM 6.5
CVE-2021-21177EPSS 17%

Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive informat…

Fix: 89.0.4389.72+
Fix from $1,600 2021-03-09
Android HIGH 7.8
CVE-2021-0336

In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local esca…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0334

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains…

Patch available
Fix from $1,950 2021-02-10
Android MEDIUM 5.5
CVE-2021-0304

In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa…

Mitigation only
Fix from $1,600 2021-01-11
Android MEDIUM 5.5
CVE-2020-0410

In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclo…

Patch available
Fix from $1,600 2020-10-14