CVE-2021-25455
- EPSS 0.06%
- Veröffentlicht 09.09.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:55:01
OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
CVE-2021-25456
- EPSS 0.06%
- Veröffentlicht 09.09.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:55:01
OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.
CVE-2021-25457
- EPSS 0.02%
- Veröffentlicht 09.09.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:55:01
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
CVE-2021-25458
- EPSS 0.02%
- Veröffentlicht 09.09.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:55:01
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
CVE-2021-25459
- EPSS 0.02%
- Veröffentlicht 09.09.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:55:01
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
CVE-2021-25460
- EPSS 0.02%
- Veröffentlicht 09.09.2021 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:55:02
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
CVE-2021-25450
- EPSS 0.05%
- Veröffentlicht 09.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:00
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.
CVE-2021-25451
- EPSS 0.06%
- Veröffentlicht 09.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:00
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
CVE-2021-25452
- EPSS 0.02%
- Veröffentlicht 09.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:00
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.
CVE-2021-25449
- EPSS 0.18%
- Veröffentlicht 09.09.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:00
An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.