Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2021-1004

In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-1017

In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permiss…

Mitigation only
Fix from $1,950 2021-12-15
Android MEDIUM 5.5
CVE-2021-1010

In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no addit…

Mitigation only
Fix from $1,600 2021-12-15
Android MEDIUM 5.5
CVE-2021-1011

In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no…

Mitigation only
Fix from $1,600 2021-12-15
Android HIGH 7.8
CVE-2021-0985

In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local esca…

Patch available
Fix from $1,950 2021-12-15
Android MEDIUM 5.5
CVE-2021-0986

In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device a…

Patch available
Fix from $1,600 2021-12-15
Android HIGH 8.8
CVE-2021-0965

In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This …

Patch available
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0922

In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a miss…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0923

In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to loca…

Mitigation only
Fix from $1,950 2021-12-15
Android HIGH 7.8
CVE-2021-0926

In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This c…

Mitigation only
Fix from $1,950 2021-12-15
Android MEDIUM 5.5
CVE-2021-0653

In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission ch…

Mitigation only
Fix from $1,600 2021-12-15
Android MEDIUM 5.5
CVE-2021-0672

In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no…

Mitigation only
Fix from $1,600 2021-11-18
Android MEDIUM 5.5
CVE-2021-0706

In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This coul…

Mitigation only
Fix from $1,600 2021-10-22
Android MEDIUM 5.5
CVE-2021-0643

In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due t…

Mitigation only
Fix from $1,600 2021-10-22
Chrome MEDIUM 6.5
CVE-2021-37976 KEVEPSS 20%

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 94.0.4606.71+
Fix from $1,600 2021-10-08
Android MEDIUM 5.5
CVE-2021-0680

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0681

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0682

In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. …

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0686

In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user d…

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0415

In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information discl…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 5.5
CVE-2021-0641

In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission …

Patch available
Fix from $1,600 2021-08-17
Android MEDIUM 5.5
CVE-2021-0642

In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permis…

Patch available
Fix from $1,600 2021-08-17
Android MEDIUM 5.5
CVE-2021-0518

In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with…

Mitigation only
Fix from $1,600 2021-07-14
Android MEDIUM 5.5
CVE-2021-0597

In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission …

Mitigation only
Fix from $1,600 2021-07-14
Android MEDIUM 5.5
CVE-2021-0654

In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information …

Mitigation only
Fix from $1,600 2021-07-14
Android HIGH 7.8
CVE-2021-0539

In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permis…

Mitigation only
Fix from $1,950 2021-06-22
Android HIGH 7.8
CVE-2021-0547

In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permi…

Mitigation only
Fix from $1,950 2021-06-22
Android HIGH 7.8
CVE-2021-0568

In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead…

Mitigation only
Fix from $1,950 2021-06-22
Android MEDIUM 5.5
CVE-2021-0554

In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no a…

Mitigation only
Fix from $1,600 2021-06-22
Android HIGH 7.8
CVE-2021-0505

In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of pr…

Patch available
Fix from $1,950 2021-06-21