Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 6.5 CVE-2019-9380 In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permi… Android Mitigation only Fix from $1,6002019-09-27 MEDIUM 5.3 CVE-2019-9323 In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper … Android Mitigation only Fix from $1,6002019-09-27 HIGH 7.8 CVE-2019-9295 In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local… Android Mitigation only Fix from $1,9502019-09-27 HIGH 7.8 CVE-2019-9263 In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of pr… Android Mitigation only Fix from $1,9502019-09-27 MEDIUM 5.5 CVE-2019-2137 In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local d… Android Mitigation only Fix from $1,6002019-08-20 MEDIUM 5.5 CVE-2019-2117 In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead t… Android Mitigation only Fix from $1,6002019-07-08 HIGH 8.8 CVE-2019-2005 In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. Th… Android Mitigation only Fix from $1,9502019-06-19 HIGH 7.8 CVE-2019-2091 In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission ch… Android Mitigation only Fix from $1,9502019-06-07 HIGH 7.8 CVE-2019-2092 In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a missing permission check. Th… Android Mitigation only Fix from $1,9502019-06-07 HIGH 7.8 CVE-2019-2098 In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permissions bypass due to a missing permissions check. T… Android Mitigation only Fix from $1,9502019-06-07 HIGH 7.8 CVE-2019-2090 In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing permissions check. This could… Android Mitigation only Fix from $1,9502019-06-07 HIGH 7.8 CVE-2019-2026 In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local… Android Patch available Fix from $1,9502019-04-19 HIGH 8.8 CVE-2019-5774 Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacke… Chrome 72.0.3626.81+ Fix from $1,9502019-02-19 HIGH 7.4 CVE-2018-16081 Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user t… Chrome 69.0.3497.81+ Fix from $1,9502019-01-09 MEDIUM 5.5 CVE-2018-9548 In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. This could lead to local inform… Android Patch available Fix from $1,6002018-12-06 MEDIUM 5.5 CVE-2018-9457 In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This cou… Android Patch available Fix from $1,6002018-11-14 HIGH 7.8 CVE-2017-13247 In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileg… Android Mitigation only Fix from $1,9502018-02-12 HIGH 7.8 CVE-2017-13209 In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which coul… Android No fix yet Fix from $1,9502018-01-12 HIGH 7.8 CVE-2017-11042 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, ImsService and the IQtiImsExt AIDL AP… Android Mitigation only Fix from $1,9502017-12-05 HIGH 7.8 CVE-2017-0554 An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its p… Android Mitigation only Fix from $1,9502017-04-07