|
198451
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-0734
|
2024-11-21 14:43 |
2022-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198452
|
7.8 |
HIGH
Local
|
google
|
android
|
In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User i…
|
CWE-416
Use After Free
|
CVE-2021-0707
|
2024-11-21 14:43 |
2022-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198453
|
7.8 |
HIGH
Local
|
google
|
android
|
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This coul…
|
CWE-863
Incorrect Authorization
|
CVE-2021-0694
|
2024-11-21 14:43 |
2022-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198454
|
7.8 |
HIGH
Local
|
google
|
android
|
In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User exec…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-1033
|
2024-11-21 14:43 |
2022-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198455
|
7.8 |
HIGH
Local
|
google
|
android
|
In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no add…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-1000
|
2024-11-21 14:43 |
2022-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198456
|
7.8 |
HIGH
Local
|
google
|
android
|
In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset Protections. This could lead to local escalation of privilege with no additiona…
|
NVD-CWE-noinfo
|
CVE-2021-0957
|
2024-11-21 14:43 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198457
|
9.8 |
CRITICAL
Network
|
google
|
android
|
Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722
|
NVD-CWE-noinfo
|
CVE-2021-1049
|
2024-11-21 14:43 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198458
|
5.3 |
MEDIUM
Network
|
google
|
android
|
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are p…
|
CWE-862
Missing Authorization
|
CVE-2021-1037
|
2024-11-21 14:43 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198459
|
7.8 |
HIGH
Local
|
google
|
android
|
In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privilege…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-1036
|
2024-11-21 14:43 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198460
|
7.8 |
HIGH
Local
|
google
|
android
|
In setLaunchIntent of BluetoothDevicePickerPreferenceController.java, there is a possible way to invoke an arbitrary broadcast receiver due to a confused deputy. This could lead to local escalation o…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2021-1035
|
2024-11-21 14:43 |
2022-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|