|
196311
|
7.8 |
HIGH
Local
|
google
|
android
|
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.
|
CWE-20
Improper Input Validation
|
CVE-2021-25517
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196312
|
7.5 |
HIGH
Network
|
google
|
android
|
An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-25516
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196313
|
3.3 |
LOW
Local
|
google
|
android
|
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-25515
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196314
|
6.5 |
MEDIUM
Network
|
google
|
android
|
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.
|
NVD-CWE-Other
|
CVE-2021-25514
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196315
|
2.4 |
LOW
Physics
|
google
|
android
|
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.
|
CWE-269
Improper Privilege Management
|
CVE-2021-25513
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196316
|
7.8 |
HIGH
Local
|
google
|
android
|
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.
|
CWE-20
Improper Input Validation
|
CVE-2021-25512
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196317
|
7.8 |
HIGH
Local
|
google
|
android
|
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.
|
CWE-22
Path Traversal
|
CVE-2021-25511
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196318
|
7.8 |
HIGH
Local
|
google
|
android
|
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.
|
CWE-20
Improper Input Validation
|
CVE-2021-25510
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196319
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortios
|
An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically cr…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-26109
|
2024-11-21 14:55 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196320
|
7.5 |
HIGH
Network
|
fortinet
|
fortios
|
A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-26108
|
2024-11-21 14:55 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|