Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2022-20274

In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User executi…

Mitigation only
Fix from $1,950 2022-08-12
Android HIGH 7.8
CVE-2022-20281

In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2022-08-12
Android HIGH 7.8
CVE-2022-20282

In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation…

Mitigation only
Fix from $1,950 2022-08-12
Android MEDIUM 5.5
CVE-2022-20284

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of phone …

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20259

In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no ad…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2022-20263

In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disc…

Mitigation only
Fix from $1,600 2022-08-12
Android MEDIUM 5.5
CVE-2021-0735

In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing…

Mitigation only
Fix from $1,600 2022-08-11
Android HIGH 7.8
CVE-2022-20360

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the g…

Patch available
Fix from $1,950 2022-08-10
Android HIGH 7.8
CVE-2022-20348

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission che…

Patch available
Fix from $1,950 2022-08-10
Android HIGH 7.8
CVE-2022-20349

In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permissi…

Patch available
Fix from $1,950 2022-08-10
Android MEDIUM 5.5
CVE-2022-20352

In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a m…

Patch available
Fix from $1,600 2022-08-10
Android HIGH 7.8
CVE-2022-26429

In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2022-08-01
Android MEDIUM 5.5
CVE-2022-20225

In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This…

Patch available
Fix from $1,600 2022-07-13
Android HIGH 7.8
CVE-2022-21777

In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additi…

Mitigation only
Fix from $1,950 2022-07-06
Android MEDIUM 5.5
CVE-2022-21763

In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure wit…

Mitigation only
Fix from $1,600 2022-07-06
Android MEDIUM 5.5
CVE-2022-21764

In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure wit…

Mitigation only
Fix from $1,600 2022-07-06
Android HIGH 7.8
CVE-2022-20204

In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permi…

Mitigation only
Fix from $1,950 2022-06-15
Android MEDIUM 5.5
CVE-2022-20200

In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local informa…

Mitigation only
Fix from $1,600 2022-06-15
Android MEDIUM 5.5
CVE-2022-20206

In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclos…

Mitigation only
Fix from $1,600 2022-06-15
Android MEDIUM 5.5
CVE-2022-20172

In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local informati…

Mitigation only
Fix from $1,600 2022-06-15
Android HIGH 7.8
CVE-2022-20138

In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVIS…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.8
CVE-2022-20133

In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead t…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.3
CVE-2022-20126

In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permissio…

Mitigation only
Fix from $1,950 2022-06-15
Android HIGH 7.3
CVE-2022-20137

In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permissi…

Patch available
Fix from $1,950 2022-06-15
Android MEDIUM 5.5
CVE-2022-21748

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User…

Mitigation only
Fix from $1,600 2022-06-06
Android MEDIUM 5.5
CVE-2022-21749

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2022-06-06
Android MEDIUM 5.5
CVE-2022-20121

In getNodeValue of USCCDMPlugin.java, there is a possible disclosure of ICCID due to a missing permission check. This could lead to local information…

Mitigation only
Fix from $1,600 2022-05-10
Android HIGH 7.8
CVE-2021-39738

In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation …

Mitigation only
Fix from $1,950 2022-05-10
Android MEDIUM 5.5
CVE-2022-20011

In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead …

Patch available
Fix from $1,600 2022-05-10
Android MEDIUM 5.5
CVE-2022-20115

In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due …

Patch available
Fix from $1,600 2022-05-10