- EPSS 0.06%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:05
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.
CVE-2021-25486
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:05
Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.
CVE-2021-25488
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:05
Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.
- EPSS 0.03%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:05
A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.
CVE-2021-25491
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:06
A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.
CVE-2021-25467
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.
CVE-2021-25468
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.
CVE-2021-25469
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.
CVE-2021-25470
- EPSS 0.04%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
CVE-2021-25471
- EPSS 0.11%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.