Skip to content

CVEs

索引

漏洞列表

2025

CVECVSSCWE层级组件概述ITW
CVE-2025-682607.8CWE-416KernelBinderBinder driver vulnerability
CVE-2025-486337.8CWE-416KernelBinderBinder driver vulnerability
CVE-2025-485937.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-485547.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-485457.8CWE-269FrameworkSystem/FrameworkFramework component vulnerability
CVE-2025-485437.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-485357.8CWE-269NativeSystem/CoreNative system component vulnerability
CVE-2025-485307.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-485247.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-383527.8CWE-416KernelKernel/CoreKernel component vulnerability
CVE-2025-323237.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-273638.1CWE-787NativeSystem/FreeTypeFreeType font subglyph OOB write → code execution (ITW, zero-click)
CVE-2025-264647.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-264437.8CWE-269FrameworkSystem/FrameworkFramework component vulnerability
CVE-2025-224327.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-224137.8CWE-787KernelKernel/CoreKernel component vulnerability
CVE-2025-206555.5CWE-200NativeKeystore/TEEMediaTek Keymaster TEE information disclosure
CVE-2025-00917.8CWE-416NativeSystem/CoreNative system component vulnerability
CVE-2025-00787.8CWE-416KernelKernel/CoreKernel component vulnerability
CVE-2025-00767.8CWE-269FrameworkSystem/FrameworkFramework privilege escalation

2024

CVECVSSCWE层级组件概述ITW
CVE-2024-531977.8CWE-787KernelKernel/ALSA-USBLinux kernel ALSA USB-audio OOB memory access (ITW, Cellebrite chain)
CVE-2024-531507.1CWE-125KernelKernel/ALSA-USBLinux kernel ALSA USB-audio OOB read (ITW, Cellebrite chain)
CVE-2024-531047.8CWE-787KernelKernel/USB-UVCLinux kernel USB Video Class OOB write (ITW, Cellebrite chain)
CVE-2024-503027.8CWE-908KernelKernel/HIDLinux kernel HID core uninitialized buffer → info leak (ITW, Cellebrite chain)
CVE-2024-497447.8CWE-502FrameworkAMS/AccountManagerAccountManagerService unsafe deserialization → EoP
CVE-2024-497335.5CWE-269FrameworkSystem/SettingsServiceListing reload logic error → hide NLS from Settings
CVE-2024-497217.8CWE-269FrameworkFramework/CoreFramework privilege escalation
CVE-2024-454455.5CWE-200NativeKeystore/TEEKeystore/TEE information disclosure
CVE-2024-430937.8CWE-22FrameworkFramework/ExternalStorageExternalStorageProvider Unicode normalization path traversal (ITW)
CVE-2024-430905.0CWE-862FrameworkFramework/CoreMissing permission check → cross-user image read
CVE-2024-430817.8CWE-269FrameworkPMSInstallPackageHelper carrier restriction bypass → EoP
CVE-2024-430807.8CWE-502FrameworkSystem/SettingsAppRestrictionsFragment unsafe deserialization → EoP (Intent Redirect)
CVE-2024-406607.8CWE-269FrameworkFramework/CoreFramework component privilege escalation
CVE-2024-406527.8CWE-862FrameworkSystem/SettingsSettingsHomepageActivity missing permission check → EoP during provisioning
CVE-2024-406507.8CWE-862FrameworkSystem/SettingsSettings FRP bypass via wifi_item_edit_content
CVE-2024-369717.8CWE-416KernelKernel/NetworkingLinux kernel __dst_negative_advice() UAF (ITW, Google TAG)
CVE-2024-328967.8CWE-269FrameworkPixel/FirmwarePixel firmware logic error → privilege escalation (ITW, factory reset interrupt)
CVE-2024-313207.8CWE-862FrameworkFramework/CDMCompanionDeviceManager setSkipPrompt bypass
CVE-2024-297797.8CWE-269NativeKeystore/KeyMintKeyMint TEE privilege escalation
CVE-2024-297455.5CWE-200BootloaderPixel/FastbootPixel fastboot firmware memory not zeroed → info disclosure (ITW, Cellebrite)
CVE-2024-208656.8CWE-287BootloaderSamsung/BootloaderSamsung bootloader authentication bypass → flash arbitrary images
CVE-2024-208326.7CWE-787BootloaderSamsung/BootloaderSamsung Little Kernel bootloader heap overflow
CVE-2024-00447.8CWE-20FrameworkPMSPackageInstallerService installer name injection → run-as bypass (ITW)
CVE-2024-00257.8CWE-269FrameworkAMSsendIntentSender logic error → background activity launch

2023

CVECVSSCWE层级组件概述ITW
CVE-2023-48638.8CWE-787NativeSystem/libwebplibwebp heap buffer overflow in BuildHuffmanTable (ITW)
CVE-2023-42117.8CWE-416KernelGPU/MaliARM Mali GPU driver use-after-free (ITW)
CVE-2023-212557.8CWE-416KernelBinderBinder driver use-after-free
CVE-2023-210365.5CWE-200FrameworkSystem/MarkupaCropalypse — Markup screenshot data not truncated
CVE-2023-209387.8CWE-416KernelBinderBinder driver use-after-free in binder_transaction

2022

CVECVSSCWE层级组件概述ITW
CVE-2022-45435.5CWE-281KernelKernel/CoreEntryBleed — KASLR bypass via prefetch side-channel
CVE-2022-201867.8CWE-787KernelGPU/MaliARM Mali GPU driver out-of-bounds write
CVE-2022-08477.8CWE-281KernelKernel/CoreDirty Pipe — pipe buffer flag not cleared on splice

2021

CVECVSSCWE层级组件概述ITW
CVE-2021-19057.8CWE-416KernelGPU/AdrenoQualcomm Adreno GPU use-after-free (ITW)
CVE-2021-10487.8CWE-416KernelKernel/Coreepoll use-after-free in ep_loop_check_proc (ITW)
CVE-2021-09287.8CWE-416KernelBinderParcel deserialization type confusion via OutputConfiguration
CVE-2021-09207.8CWE-416KernelKernel/AF_UNIXAF_UNIX garbage collection race condition (ITW, Google TAG)
CVE-2021-04787.8CWE-269FrameworkPMSPendingIntent hijack in PackageManagerService