|
196051
|
7.8 |
HIGH
Local
|
google
|
android
|
In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privil…
|
CWE-20 NVD-CWE-Other
Improper Input Validation
|
CVE-2021-0511
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196052
|
7.8 |
HIGH
Local
|
google
|
android
|
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2021-0510
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196053
|
7.0 |
HIGH
Local
|
google
|
android
|
In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2021-0509
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196054
|
7.0 |
HIGH
Local
|
google
|
android
|
In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2021-0508
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196055
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution pri…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-0507
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196056
|
7.3 |
HIGH
Local
|
google
|
android
|
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution pr…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-0506
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196057
|
7.8 |
HIGH
Local
|
google
|
android
|
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne…
|
CWE-862
Missing Authorization
|
CVE-2021-0505
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196058
|
6.5 |
MEDIUM
Adjacent
|
google
|
android
|
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional ex…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-0504
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196059
|
7.8 |
HIGH
Local
|
google
|
android
|
In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services withou…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-0478
|
2024-11-21 14:42 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196060
|
7.8 |
HIGH
Local
|
intel
|
brand_verification_tool
|
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local acces…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-0143
|
2024-11-21 14:42 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|