CVE-2021-25468
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.
CVE-2021-25469
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.
CVE-2021-25470
- EPSS 0.04%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
CVE-2021-25471
- EPSS 0.11%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.
CVE-2021-25472
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
CVE-2021-25473
- EPSS 0.05%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset...
CVE-2021-25474
- EPSS 0.05%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.
CVE-2021-25475
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:04
A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
CVE-2021-0690
- EPSS 1.13%
- Veröffentlicht 06.10.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:43:09
In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed...
CVE-2021-0691
- EPSS 0.03%
- Veröffentlicht 06.10.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:43:09
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution pri...