Latest CVE Feed
-
5.5
MEDIUMCVE-2021-39779
In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for exploitation.Product:... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-27187
After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i... Read more
- Published: Apr. 08, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2021-39756
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User int... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39774
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Androi... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39751
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39769
In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interact... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39753
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39748
In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39754
In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User i... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39775
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User intera... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39761
In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interac... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39778
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39700
In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp... Read more
Affected Products : android- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-23245
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to access global resources. A successful exploit of this vulnerability might lead to denial of service.... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 02, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2021-39773
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39690
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not ne... Read more
Affected Products : android- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39670
In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Pro... Read more
Affected Products : android- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39765
In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39747
In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex... Read more
Affected Products : android- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-22010
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup during bt pages loop Driver runs a for-loop when allocating bt pages and mapping them with buffer pages. When a large buffer (e.g. MR over 100GB) is being allo... Read more
Affected Products : linux_kernel- Published: Apr. 08, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Denial of Service