Latest CVE Feed
-
5.5
MEDIUMCVE-2021-0484
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0483
In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-0482
In BinderDiedCallback of MediaCodec.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Produc... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-0481
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ne... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0480
In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0478
In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services without notifying the user, with User execution privileges nee... Read more
Affected Products : android- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0477
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not neede... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-0476
In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-0475
In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitatio... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-0474
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Andr... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-0473
In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0472
In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0471
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:... Read more
Affected Products : android- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2021-0468
In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is... Read more
Affected Products : android- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-0467
In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interaction... Read more
Affected Products : android- Published: Jun. 14, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-0466
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User interaction is not... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0465
In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Prod... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-0464
In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0463
In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for e... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-0462
In the NXP NFC firmware, there is a possible insecure firmware update due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024