Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.8 CVE-2022-20004 In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to loca… Android Patch available Fix from $1,9502022-05-10 HIGH 7.8 CVE-2022-20084 In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalatio… Android Mitigation only Fix from $1,9502022-05-03 HIGH 7.8 CVE-2022-20093 In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of pri… Android Mitigation only Fix from $1,9502022-05-03 HIGH 7.8 CVE-2021-39808 In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due… Android Patch available Fix from $1,9502022-04-12 HIGH 7.8 CVE-2022-20002 In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39768 In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lea… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39743 In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to loc… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39749 In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39750 In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to loca… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39758 In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to lo… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 5.5 CVE-2021-39742 In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disc… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39751 In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to … Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39753 In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lea… Android Mitigation only Fix from $1,6002022-03-30 HIGH 7.8 CVE-2021-39734 In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check… Android Mitigation only Fix from $1,9502022-03-16 HIGH 7.8 CVE-2021-39706 In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This coul… Android Patch available Fix from $1,9502022-03-16 HIGH 7.8 CVE-2021-39697 In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missi… Android Patch available Fix from $1,9502022-03-16 HIGH 7.8 CVE-2022-20054 In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no … Android Mitigation only Fix from $1,9502022-03-10 HIGH 7.8 CVE-2022-20053 In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502022-03-10 MEDIUM 6.7 CVE-2022-20049 In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e… Android Mitigation only Fix from $1,6002022-03-10 HIGH 7.8 CVE-2021-39662 In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing pe… Android Patch available Fix from $1,9502022-02-11 HIGH 7.8 CVE-2022-20041 In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no… Android Mitigation only Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-20043 In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no… Android Mitigation only Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-20024 In system service, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no … Android Mitigation only Fix from $1,9502022-02-09 HIGH 7.8 CVE-2021-39622 In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privi… Android Mitigation only Fix from $1,9502022-01-14 MEDIUM 5.3 CVE-2021-1037 The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for i… Android Mitigation only Fix from $1,6002022-01-14 HIGH 7.8 CVE-2021-0673 In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502021-12-17 HIGH 7.8 CVE-2021-39651 In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead… Android Patch available Fix from $1,9502021-12-15 MEDIUM 6.8 CVE-2021-39639 In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege w… Android Patch available Fix from $1,6002021-12-15 MEDIUM 5.5 CVE-2021-1025 In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, du… Android Mitigation only Fix from $1,6002021-12-15 HIGH 7.8 CVE-2021-0999 In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permis… Android Patch available Fix from $1,9502021-12-15