Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.8 CVE-2021-1004 In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to… Android Mitigation only Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-1017 In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permiss… Android Mitigation only Fix from $1,9502021-12-15 MEDIUM 5.5 CVE-2021-1010 In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no addit… Android Mitigation only Fix from $1,6002021-12-15 MEDIUM 5.5 CVE-2021-1011 In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no… Android Mitigation only Fix from $1,6002021-12-15 HIGH 7.8 CVE-2021-0985 In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local esca… Android Patch available Fix from $1,9502021-12-15 MEDIUM 5.5 CVE-2021-0986 In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device a… Android Patch available Fix from $1,6002021-12-15 HIGH 8.8 CVE-2021-0965 In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This … Android Patch available Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-0922 In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a miss… Android Mitigation only Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-0923 In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to loca… Android Mitigation only Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-0926 In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This c… Android Mitigation only Fix from $1,9502021-12-15 MEDIUM 5.5 CVE-2021-0653 In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission ch… Android Mitigation only Fix from $1,6002021-12-15 MEDIUM 5.5 CVE-2021-0672 In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no… Android Mitigation only Fix from $1,6002021-11-18 MEDIUM 5.5 CVE-2021-0706 In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This coul… Android Mitigation only Fix from $1,6002021-10-22 MEDIUM 5.5 CVE-2021-0643 In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due t… Android Mitigation only Fix from $1,6002021-10-22 MEDIUM 6.5 CVE-2021-37976 KEVEPSS 20% Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information f… Chrome 94.0.4606.71+ Fix from $1,6002021-10-08 MEDIUM 5.5 CVE-2021-0680 In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w… Android Mitigation only Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0681 In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w… Android Mitigation only Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0682 In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. … Android Patch available Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0686 In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user d… Android Patch available Fix from $1,6002021-10-06 MEDIUM 5.5 CVE-2021-0415 In memory management driver, there is a possible information disclosure due to a missing permission check. This could lead to local information discl… Android Mitigation only Fix from $1,6002021-08-18 MEDIUM 5.5 CVE-2021-0641 In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission … Android Patch available Fix from $1,6002021-08-17 MEDIUM 5.5 CVE-2021-0642 In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permis… Android Patch available Fix from $1,6002021-08-17 MEDIUM 5.5 CVE-2021-0518 In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with… Android Mitigation only Fix from $1,6002021-07-14 MEDIUM 5.5 CVE-2021-0597 In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission … Android Mitigation only Fix from $1,6002021-07-14 MEDIUM 5.5 CVE-2021-0654 In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information … Android Mitigation only Fix from $1,6002021-07-14 HIGH 7.8 CVE-2021-0539 In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permis… Android Mitigation only Fix from $1,9502021-06-22 HIGH 7.8 CVE-2021-0547 In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permi… Android Mitigation only Fix from $1,9502021-06-22 HIGH 7.8 CVE-2021-0568 In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead… Android Mitigation only Fix from $1,9502021-06-22 MEDIUM 5.5 CVE-2021-0554 In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no a… Android Mitigation only Fix from $1,6002021-06-22 HIGH 7.8 CVE-2021-0505 In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of pr… Android Patch available Fix from $1,9502021-06-21