- EPSS 1.1%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:18
In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interac...
CVE-2021-0958
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:18
In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Pro...
CVE-2021-0961
- EPSS 0.05%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Prod...
CVE-2021-0963
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...
CVE-2021-0964
- EPSS 0.37%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In C2SoftMP3::process() of C2SoftMp3Dec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploi...
CVE-2021-0965
- EPSS 0.04%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVE-2021-0966
- EPSS 0.02%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:43:19
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder t...
CVE-2021-0434
- EPSS 0.03%
- Veröffentlicht 15.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:42:43
In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local ...
CVE-2021-0649
- EPSS 0.01%
- Veröffentlicht 15.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:43:04
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed fo...
CVE-2021-0650
- EPSS 0.47%
- Veröffentlicht 15.12.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:43:04
In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploi...