|
196081
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privilege…
|
CWE-416
Use After Free
|
CVE-2021-0475
|
2024-11-21 14:42 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196082
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-0474
|
2024-11-21 14:42 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196083
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2021-0473
|
2024-11-21 14:42 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196084
|
7.8 |
HIGH
Local
|
google
|
android
|
In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no addit…
|
CWE-863
Incorrect Authorization
|
CVE-2021-0472
|
2024-11-21 14:42 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196085
|
7.5 |
HIGH
Network
|
google
|
android
|
In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additio…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-0466
|
2024-11-21 14:42 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196086
|
4.9 |
MEDIUM
Network
|
intel
|
secl-dc
|
Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to potentially enable denial of service via network access.
|
CWE-20
Improper Input Validation
|
CVE-2021-0134
|
2024-11-21 14:42 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196087
|
8.1 |
HIGH
Network
|
intel
|
secl-dc
|
Key exchange without entity authentication in the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable escalation of privilege via network access.
|
NVD-CWE-Other
|
CVE-2021-0133
|
2024-11-21 14:42 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196088
|
4.9 |
MEDIUM
Network
|
intel
|
secl-dc
|
Missing release of resource after effective lifetime in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to potentially enable denial of service via network acc…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2021-0132
|
2024-11-21 14:42 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196089
|
6.5 |
MEDIUM
Network
|
intel
|
secl-dc
|
Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before version 3.3 may allow an authenticated user to potentially enable information di…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2021-0131
|
2024-11-21 14:42 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196090
|
5.7 |
MEDIUM
Adjacent
|
bluez redhat debian
|
bluez enterprise_linux debian_linux
|
Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.
|
NVD-CWE-Other
|
CVE-2021-0129
|
2024-11-21 14:42 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|