Latest CVE Feed
-
5.5
MEDIUMCVE-2021-0887
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio... Read more
Affected Products : android- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0871
In PVRSRVBridgePMRPDumpSymbolicAddr of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution pri... Read more
Affected Products : android- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-0870
In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-0869
In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitatio... Read more
Affected Products : android- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0799
In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi... Read more
Affected Products : android- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-0769
In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to unclear UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for ... Read more
Affected Products : android- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0735
In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced in Android 11 due to a missing permission check. This could lead to local information disclosure with no additional execution privileges... Read more
Affected Products : android- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0734
In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissions,... Read more
Affected Products : android- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0708
In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0707
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andro... Read more
Affected Products : android- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0706
In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not ... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0705
In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions. This could lead to local escalation of privilege with no additi... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0704
In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions due to a permissions bypass. This could lead to local information disclosure... Read more
Affected Products : android- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-0703
In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to local escalation of privilege if the attacker has physical access to the device, with no additional execution privileges needed. User ... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0702
In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore downgrade. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed ... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0698
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.P... Read more
Affected Products : android- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-0697
In PVRSRVRGXSubmitTransferKM of rgxtransfer.c, there is a possible user after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Pr... Read more
Affected Products : android- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-0696
In dllist_remove_node of TBD, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android... Read more
Affected Products : android- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0695
In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more
Affected Products : android- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0694
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no addition... Read more
Affected Products : android- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024