CVE-2021-25444
- EPSS 0.03%
- Veröffentlicht 05.08.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:59
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
CVE-2020-0417
- EPSS 0.01%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 04:53:28
In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed ...
CVE-2021-0441
- EPSS 0.01%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:43
In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: A...
CVE-2021-0486
- EPSS 0.01%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:48
In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not need...
CVE-2021-0514
- EPSS 1.41%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:50
In several functions of the V8 library, there is a possible use after free due to a race condition. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for...
- EPSS 2.18%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:50
In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User inte...
CVE-2021-0518
- EPSS 0.01%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:51
In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVE-2021-0577
- EPSS 0.01%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:57
In flv extractor, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android...
CVE-2021-0585
- EPSS 0.03%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:58
In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ...
CVE-2021-0586
- EPSS 0.03%
- Veröffentlicht 14.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:42:58
In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges ne...