|
196321
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution priv…
|
CWE-125 CWE-787 CWE-416
Out-of-bounds Read Out-of-bounds Write Use After Free
|
CVE-2021-0516
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196322
|
7.8 |
HIGH
Local
|
google
|
android
|
In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of p…
|
CWE-862
Missing Authorization
|
CVE-2021-0513
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196323
|
7.8 |
HIGH
Local
|
google
|
android
|
In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-0512
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196324
|
7.8 |
HIGH
Local
|
google
|
android
|
In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privil…
|
CWE-20 NVD-CWE-Other
Improper Input Validation
|
CVE-2021-0511
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196325
|
7.8 |
HIGH
Local
|
google
|
android
|
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2021-0510
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196326
|
7.0 |
HIGH
Local
|
google
|
android
|
In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2021-0509
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196327
|
7.0 |
HIGH
Local
|
google
|
android
|
In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2021-0508
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196328
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution pri…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-0507
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196329
|
7.3 |
HIGH
Local
|
google
|
android
|
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution pr…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-0506
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196330
|
7.8 |
HIGH
Local
|
google
|
android
|
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne…
|
CWE-862
Missing Authorization
|
CVE-2021-0505
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|