CVE-2020-27098
- EPSS 0.01%
- Veröffentlicht 26.01.2021 18:15:45
- Zuletzt bearbeitet 21.11.2024 05:20:45
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is no...
CVE-2020-0236
- EPSS 0.31%
- Veröffentlicht 26.01.2021 18:15:31
- Zuletzt bearbeitet 21.11.2024 04:53:09
In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVE-2021-0304
- EPSS 0.02%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:27
In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of the user's contacts with User execution privileges needed. User interaction is not...
CVE-2021-0306
- EPSS 0.01%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:27
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation. This cou...
CVE-2021-0307
- EPSS 0.03%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. This could lead to local escalation of privilege allowing a malicious app to silently gain access to a...
CVE-2021-0308
- EPSS 0.08%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVE-2021-0309
- EPSS 0.02%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disclosure and account access with no additional execution privileges needed. User interaction is needed for exploitation. Product: An...
CVE-2021-0310
- EPSS 0.02%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...
CVE-2021-0311
- EPSS 0.2%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction...
CVE-2021-0312
- EPSS 0.2%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. ...