CVE-2021-0870
- EPSS 0.95%
- Veröffentlicht 22.10.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:43:11
In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVE-2021-0483
- EPSS 0.01%
- Veröffentlicht 22.10.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:42:47
In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVE-2021-0643
- EPSS 0.01%
- Veröffentlicht 22.10.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:43:04
In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check. This could lead to local information disclosure with User execution pri...
CVE-2021-0651
- EPSS 0.03%
- Veröffentlicht 22.10.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:43:04
In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. This could lead to local denial of service with no additional execution privileges needed. User interact...
CVE-2021-0583
- EPSS 0.01%
- Veröffentlicht 11.10.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:42:58
In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is ne...
CVE-2021-25476
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:04
An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.
CVE-2021-25477
- EPSS 0.2%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:04
An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.
CVE-2021-25478
- EPSS 0.23%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:04
A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
CVE-2021-25479
- EPSS 0.23%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:04
A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
CVE-2021-25480
- EPSS 0.31%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:04
A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.