Latest CVE Feed
-
4.4
MEDIUMCVE-2021-0666
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672086; Issue ID:... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-0665
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672113; Issue ID:... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-0664
In ccu, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827158; Issue ID: ALPS0582715... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-0663
In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844458; Issu... Read more
Affected Products : android- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-0662
In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844434; Issu... Read more
Affected Products : android- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-0661
In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844413; Issu... Read more
Affected Products : android- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-0660
In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827145; Issue ID: ALPS05827... Read more
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-0659
In apusys, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05687559; Issue ID:... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-0658
In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-0657
In apusys, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672103; Iss... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-0656
In edma driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05709376; Issue ID: ALP... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-0655
In mdlactl driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05673424; I... Read more
- Published: Nov. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0654
In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check. This could lead to local information disclosure from locked profiles with no additional execution privileges needed. User interaction is needed... Read more
Affected Products : android- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0653
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User ... Read more
Affected Products : android- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0652
In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution privileges needed. ... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0651
In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction i... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-0650
In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio... Read more
Affected Products : android- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0649
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exp... Read more
Affected Products : android- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0646
In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional execut... Read more
Affected Products : android- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0645
In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11... Read more
Affected Products : android- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024