CVE-2021-1011
- EPSS 0.02%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:23
In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVE-2021-1012
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:23
In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional...
CVE-2021-1013
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:23
In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could le...
CVE-2021-1014
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:24
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure wit...
CVE-2021-1015
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:24
In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no addition...
CVE-2021-1016
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:24
In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed....
CVE-2021-1017
- EPSS 0.02%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:24
In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges n...
CVE-2021-1018
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:24
In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional ex...
CVE-2021-1019
- EPSS 0.02%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:24
In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog. This could lead to local escalation of privilege with User execution privileges needed. User interaction is n...
CVE-2021-1020
- EPSS 0.02%
- Veröffentlicht 15.12.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:43:24
In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed....