CVE-2021-0958
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:18
In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Pro...
CVE-2021-0961
- EPSS 0.05%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVE-2021-0963
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...
CVE-2021-0964
- EPSS 0.37%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In C2SoftMP3::process() of C2SoftMp3Dec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploi...
CVE-2021-0965
- EPSS 0.04%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVE-2021-0966
- EPSS 0.02%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder t...
CVE-2021-0434
- EPSS 0.03%
- Veröffentlicht 15.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:42:43
In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local ...
CVE-2021-0649
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:43:04
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed fo...
CVE-2021-0650
- EPSS 0.47%
- Veröffentlicht 15.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:43:04
In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploi...
CVE-2021-0653
- EPSS 0.03%
- Veröffentlicht 15.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:43:05
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. ...