|
196511
|
7.8 |
HIGH
Local
|
google
|
android
|
In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-0512
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196512
|
7.8 |
HIGH
Local
|
google
|
android
|
In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privil…
|
CWE-20 NVD-CWE-Other
Improper Input Validation
|
CVE-2021-0511
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196513
|
7.8 |
HIGH
Local
|
google
|
android
|
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2021-0510
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196514
|
7.0 |
HIGH
Local
|
google
|
android
|
In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2021-0509
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196515
|
7.0 |
HIGH
Local
|
google
|
android
|
In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2021-0508
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196516
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution pri…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-0507
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196517
|
7.3 |
HIGH
Local
|
google
|
android
|
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution pr…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-0506
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196518
|
7.8 |
HIGH
Local
|
google
|
android
|
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne…
|
CWE-862
Missing Authorization
|
CVE-2021-0505
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196519
|
6.5 |
MEDIUM
Adjacent
|
google
|
android
|
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional ex…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-0504
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196520
|
7.8 |
HIGH
Local
|
google
|
android
|
In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services withou…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-0478
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|