CVE-2021-25427
- EPSS 0.06%
- Veröffentlicht 08.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:58
SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information
CVE-2021-25428
- EPSS 0.02%
- Veröffentlicht 08.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:58
Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.
CVE-2021-25429
- EPSS 0.03%
- Veröffentlicht 08.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:58
Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
CVE-2021-25430
- EPSS 0.03%
- Veröffentlicht 08.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:58
Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
CVE-2021-0536
- EPSS 0.01%
- Veröffentlicht 22.06.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 05:42:53
In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVE-2021-0537
- EPSS 0.01%
- Veröffentlicht 22.06.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 05:42:53
In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction i...
CVE-2021-0538
- EPSS 0.01%
- Veröffentlicht 22.06.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 05:42:53
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is n...
CVE-2021-0539
- EPSS 0.01%
- Veröffentlicht 22.06.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 05:42:53
In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ...
CVE-2021-0540
- EPSS 0.02%
- Veröffentlicht 22.06.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 05:42:53
In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...
CVE-2021-0541
- EPSS 0.01%
- Veröffentlicht 22.06.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 05:42:53
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User inter...