Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2022-20004

In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to loca…

Patch available
Fix from $1,950 2022-05-10
Android HIGH 7.8
CVE-2022-20084

In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2022-05-03
Android HIGH 7.8
CVE-2022-20093

In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of pri…

Mitigation only
Fix from $1,950 2022-05-03
Android HIGH 7.8
CVE-2021-39808

In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due…

Patch available
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2022-20002

In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39768

In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lea…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39743

In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to loc…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39749

In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39750

In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to loca…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39758

In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to lo…

Mitigation only
Fix from $1,950 2022-03-30
Android MEDIUM 5.5
CVE-2021-39742

In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disc…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39751

In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to …

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39753

In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lea…

Mitigation only
Fix from $1,600 2022-03-30
Android HIGH 7.8
CVE-2021-39734

In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check…

Mitigation only
Fix from $1,950 2022-03-16
Android HIGH 7.8
CVE-2021-39706

In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This coul…

Patch available
Fix from $1,950 2022-03-16
Android HIGH 7.8
CVE-2021-39697

In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missi…

Patch available
Fix from $1,950 2022-03-16
Android HIGH 7.8
CVE-2022-20054

In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2022-03-10
Android HIGH 7.8
CVE-2022-20053

In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2022-03-10
Android MEDIUM 6.7
CVE-2022-20049

In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,600 2022-03-10
Android HIGH 7.8
CVE-2021-39662

In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe…

Patch available
Fix from $1,950 2022-02-11
Android HIGH 7.8
CVE-2022-20041

In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2022-20043

In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no…

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2022-20024

In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no …

Mitigation only
Fix from $1,950 2022-02-09
Android HIGH 7.8
CVE-2021-39622

In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privi…

Mitigation only
Fix from $1,950 2022-01-14
Android MEDIUM 5.3
CVE-2021-1037

The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for i…

Mitigation only
Fix from $1,600 2022-01-14
Android HIGH 7.8
CVE-2021-0673

In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2021-12-17
Android HIGH 7.8
CVE-2021-39651

In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead…

Patch available
Fix from $1,950 2021-12-15
Android MEDIUM 6.8
CVE-2021-39639

In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege w…

Patch available
Fix from $1,600 2021-12-15
Android MEDIUM 5.5
CVE-2021-1025

In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, du…

Mitigation only
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-0999

In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permis…

Patch available
Fix from $1,950 2021-12-15