CVE-2021-0358
- EPSS 0.12%
- Veröffentlicht 03.02.2021 00:15:15
- Zuletzt bearbeitet 21.11.2024 05:42:34
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions:...
CVE-2021-0352
- EPSS 0.02%
- Veröffentlicht 03.02.2021 00:15:14
- Zuletzt bearbeitet 21.11.2024 05:42:33
In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android...
CVE-2020-27097
- EPSS 0.01%
- Veröffentlicht 26.01.2021 18:15:45
- Zuletzt bearbeitet 21.11.2024 05:20:45
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produc...
CVE-2020-27098
- EPSS 0.02%
- Veröffentlicht 26.01.2021 18:15:45
- Zuletzt bearbeitet 21.11.2024 05:20:45
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is no...
CVE-2020-0236
- EPSS 0.31%
- Veröffentlicht 26.01.2021 18:15:31
- Zuletzt bearbeitet 21.11.2024 04:53:09
In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVE-2021-0304
- EPSS 0.02%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:27
In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not...
CVE-2021-0306
- EPSS 0.01%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:27
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This cou...
CVE-2021-0307
- EPSS 0.03%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. This could lead to local escalation of privilege allowing a malicious app to silently gain access to a...
CVE-2021-0308
- EPSS 0.07%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVE-2021-0309
- EPSS 0.02%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disclosure and account access with no additional execution privileges needed. User interaction is needed for exploitation. Product: An...