Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Android HIGH 7.8
CVE-2021-0513

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state va…

Patch available
Fix from $1,950 2021-06-21
Android MEDIUM 5.5
CVE-2021-0521

In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local in…

Patch available
Fix from $1,600 2021-06-21
Android HIGH 7.8
CVE-2021-0491

In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2021-06-11
Android MEDIUM 5.5
CVE-2021-0428

In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could …

Patch available
Fix from $1,600 2021-04-13
Android HIGH 7.8
CVE-2021-0380

In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission…

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0385

In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connection to untrusted WiFi networks…

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0388

In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler. This could lead to …

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0389

In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no …

Patch available
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0390

In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. T…

Mitigation only
Fix from $1,950 2021-03-10
Android MEDIUM 5.5
CVE-2021-25344

Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without per…

Mitigation only
Fix from $1,600 2021-03-04
Android HIGH 7.8
CVE-2021-0328

In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to…

Patch available
Fix from $1,950 2021-02-10
Chrome HIGH 8.8
CVE-2020-16029

Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a craft…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Chrome MEDIUM 6.5
CVE-2020-16027

Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malic…

Fix: 87.0.4280.66+
Fix from $1,600 2021-01-08
Android HIGH 7.8
CVE-2020-27052

In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a permissions bypass. This cou…

Patch available
Fix from $1,950 2020-12-15
Android HIGH 7.8
CVE-2020-27054

In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalation of privilege with no addi…

Patch available
Fix from $1,950 2020-12-15
Android MEDIUM 5.5
CVE-2020-27032

In getRadioAccessFamily of PhoneInterfaceManager.java, there is a possible read of privileged data due to a missing permission check. This could lead…

Mitigation only
Fix from $1,600 2020-12-15
Android MEDIUM 5.5
CVE-2020-0497

In canUseBiometric of BiometricServiceBase, there is a missing permission check. This could lead to local information disclosure with no additional e…

Mitigation only
Fix from $1,600 2020-12-15
Android HIGH 7.8
CVE-2020-0475

In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. T…

Mitigation only
Fix from $1,950 2020-12-15
Android HIGH 7.8
CVE-2020-0480

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escala…

Patch available
Fix from $1,950 2020-12-15
Android HIGH 7.8
CVE-2020-0485

In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This cou…

Patch available
Fix from $1,950 2020-12-15
Android MEDIUM 5.5
CVE-2020-0477

In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This c…

Patch available
Fix from $1,600 2020-12-15
Android MEDIUM 5.5
CVE-2020-0468

In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permissi…

Patch available
Fix from $1,600 2020-12-14
Android HIGH 7.8
CVE-2020-0440

In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check.…

Patch available
Fix from $1,950 2020-12-14
Android MEDIUM 5.5
CVE-2020-0454

In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to lo…

No fix yet
Fix from $1,600 2020-11-10
Android MEDIUM 5.5
CVE-2020-0448

In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. …

Patch available
Fix from $1,600 2020-11-10
Android HIGH 7.8
CVE-2020-0439

In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to…

Patch available
Fix from $1,950 2020-11-10
Android MEDIUM 5.5
CVE-2020-0437

In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial …

Patch available
Fix from $1,600 2020-11-10
Android HIGH 7.8
CVE-2020-0420

In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escala…

Patch available
Fix from $1,950 2020-10-14
Android MEDIUM 5.5
CVE-2020-0419

In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permissi…

Patch available
Fix from $1,600 2020-10-14
Android MEDIUM 5.5
CVE-2020-0378

In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local information disclosure of location data…

Mitigation only
Fix from $1,600 2020-10-14