CVE-2021-25472
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
CVE-2021-25473
- EPSS 0.05%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset...
CVE-2021-25474
- EPSS 0.05%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:03
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.
CVE-2021-25475
- EPSS 0.02%
- Veröffentlicht 06.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:04
A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
CVE-2021-0690
- EPSS 1.13%
- Veröffentlicht 06.10.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:43:09
In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed...
CVE-2021-0691
- EPSS 0.03%
- Veröffentlicht 06.10.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:43:09
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution pri...
CVE-2021-0692
- EPSS 0.03%
- Veröffentlicht 06.10.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:43:09
In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...
CVE-2021-0693
- EPSS 0.02%
- Veröffentlicht 06.10.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:43:09
In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User i...
CVE-2021-0695
- EPSS 0.09%
- Veröffentlicht 06.10.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:43:09
In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVE-2021-0595
- EPSS 0.03%
- Veröffentlicht 06.10.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:42:59
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User in...