VYPR

CVEs

101,977 total · page 1231 of 2,040

  • CVE-2021-39651HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39646HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-201537251References: N/A

  • CVE-2021-39640HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In __dwc3_gadget_ep0_queue of ep0.c, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-1048HigKEVDec 15, 2021
    risk 0.63cvss 7.8epss 0.01

    In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-1045HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-195580473References: N/A

  • CVE-2021-1044HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In eicOpsDecryptAes128Gcm of acropora/app/identity/identity_support.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1040HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In onCreate of BluetoothPairingSelectionFragment.java, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-1039HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-1029HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1028HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1027HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1022HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.01

    In btif_in_hf_client_generic_evt of btif_hf_client.cc, there is a possible Bluetooth service crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-1021HigDec 15, 2021
    risk 0.47cvss 7.3epss 0.00

    In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed…

  • CVE-2021-1020HigDec 15, 2021
    risk 0.47cvss 7.3epss 0.00

    In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed…

  • CVE-2021-1019HigDec 15, 2021
    risk 0.47cvss 7.3epss 0.00

    In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for…

  • CVE-2021-1017HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2021-1016HigDec 15, 2021
    risk 0.47cvss 7.3epss 0.00

    In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed…

  • CVE-2021-1004HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-1003HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1002HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.01

    In WT_Interpolate of eas_wtengine.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0999HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2021-0985HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0984HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In onNullBinding of ManagedServices.java, there is a possible permission bypass due to an incorrectly unbound service. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0981HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a foreground service without showing a notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2021-0970HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0968HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.01

    In osi_malloc and osi_calloc of allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0967HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.01

    In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0965HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.00

    In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0963HigDec 15, 2021
    risk 0.46cvss 7.1epss 0.00

    In onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2021-0955HigDec 15, 2021
    risk 0.46cvss 7.0epss 0.00

    In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0954HigDec 15, 2021
    risk 0.47cvss 7.3epss 0.00

    In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2021-0953HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction…

  • CVE-2021-0933HigDec 15, 2021
    risk 0.52cvss 8.0epss 0.00

    In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to interfere with a consent dialog due to improper input validation. This could lead to remote escalation of privilege, confusing the user into accepting pairing of a…

  • CVE-2021-0932HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is…

  • CVE-2021-0930HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.01

    In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0929HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In ion_dma_buf_end_cpu_access and related functions of ion.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0928HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2021-0927HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0926HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0925HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.01

    In rw_t4t_sm_detect_ndef of rw_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure due to a limited change in behavior based on the out of bounds data with no additional execution privileges needed.…

  • CVE-2021-0924HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In xhci_vendor_get_ops of xhci.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0923HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0922HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-0921HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2021-0918HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.00

    In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0799HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0769HigDec 15, 2021
    risk 0.47cvss 7.3epss 0.00

    In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to unclear UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2021-0675HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    In alac decoder, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06064258; Issue ID:…

  • CVE-2021-0649HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0434HigDec 15, 2021
    risk 0.47cvss 7.3epss 0.00

    In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with…