CVE-2021-0946
- EPSS 0.12%
- Veröffentlicht 24.08.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 05:43:17
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it does the b...
CVE-2021-0947
- EPSS 0.12%
- Veröffentlicht 24.08.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 05:43:17
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for several reasons i...
CVE-2021-39815
- EPSS 0.15%
- Veröffentlicht 24.08.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:20:17
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: Androi...
CVE-2022-20122
- EPSS 0.16%
- Veröffentlicht 24.08.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:42:12
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: Androi...
CVE-2021-0698
- EPSS 0.02%
- Veröffentlicht 24.08.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:43:10
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...
CVE-2021-0887
- EPSS 0.02%
- Veröffentlicht 24.08.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:43:13
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...
CVE-2022-20339
- EPSS 0.02%
- Veröffentlicht 12.08.2022 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:42:37
In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. This could lead to local information disclosure of network topography with no additional execution privileges needed. User interac...
CVE-2022-20340
- EPSS 0.01%
- Veröffentlicht 12.08.2022 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:42:37
In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction...
CVE-2022-20341
- EPSS 0.01%
- Veröffentlicht 12.08.2022 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:42:37
In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User interaction is n...
CVE-2022-20342
- EPSS 0.02%
- Veröffentlicht 12.08.2022 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:42:37
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation...