CVE-2021-0333
- EPSS 0.01%
- Veröffentlicht 10.02.2021 17:15:20
- Zuletzt bearbeitet 21.11.2024 05:42:31
In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege...
CVE-2021-0334
- EPSS 0.01%
- Veröffentlicht 10.02.2021 17:15:20
- Zuletzt bearbeitet 21.11.2024 05:42:31
In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User intera...
CVE-2021-0335
- EPSS 0.29%
- Veröffentlicht 10.02.2021 17:15:20
- Zuletzt bearbeitet 21.11.2024 05:42:32
In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: An...
CVE-2021-0326
- EPSS 13.11%
- Veröffentlicht 10.02.2021 17:15:19
- Zuletzt bearbeitet 21.11.2024 05:42:31
In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed...
CVE-2021-0327
- EPSS 0.01%
- Veröffentlicht 10.02.2021 17:15:19
- Zuletzt bearbeitet 21.11.2024 05:42:31
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...
CVE-2021-0328
- EPSS 0.02%
- Veröffentlicht 10.02.2021 17:15:19
- Zuletzt bearbeitet 21.11.2024 05:42:31
In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional exec...
CVE-2021-0329
- EPSS 0.03%
- Veröffentlicht 10.02.2021 17:15:19
- Zuletzt bearbeitet 21.11.2024 05:42:31
In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth server with User execution privileges needed. User i...
CVE-2021-0330
- EPSS 0.03%
- Veröffentlicht 10.02.2021 17:15:19
- Zuletzt bearbeitet 21.11.2024 05:42:31
In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed...
CVE-2021-0314
- EPSS 0.01%
- Veröffentlicht 10.02.2021 17:15:18
- Zuletzt bearbeitet 21.11.2024 05:42:29
In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction...
CVE-2021-0325
- EPSS 4.1%
- Veröffentlicht 10.02.2021 17:15:18
- Zuletzt bearbeitet 21.11.2024 05:42:30
In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitati...