CVE-2021-25392
- EPSS 0.01%
- Veröffentlicht 11.06.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:54
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.
CVE-2021-25393
- EPSS 0.03%
- Veröffentlicht 11.06.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:54
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
CVE-2021-25382
- EPSS 0.02%
- Veröffentlicht 23.04.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:52
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
CVE-2021-0488
- EPSS 0.01%
- Veröffentlicht 15.04.2021 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:42:48
In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVE-2021-0435
- EPSS 1.56%
- Veröffentlicht 13.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:43
In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...
CVE-2021-0436
- EPSS 0.03%
- Veröffentlicht 13.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:43
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...
CVE-2021-0437
- EPSS 0.03%
- Veröffentlicht 13.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:43
In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVE-2021-0438
- EPSS 0.03%
- Veröffentlicht 13.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:43
In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjacking attack due to an incorrect FLAG_OBSCURED value. This could lead to local escalation of privilege with no additional execution pr...
CVE-2021-0439
- EPSS 0.03%
- Veröffentlicht 13.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:43
In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVE-2021-0442
- EPSS 0.02%
- Veröffentlicht 13.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:43
In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...