CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-39687

    Last Modified: 21 Nov 2024

    In HandleTransactionIoEvent of actuator_driver.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204421047References: N/A

    Published: 11 Feb 2022
    5.5
    Medium

    CVE-2021-0524

    Last Modified: 21 Nov 2024

    In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-180418334

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39672

    Last Modified: 21 Nov 2024

    In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android SoC Android ID: A-202018701

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39676

    Last Modified: 21 Nov 2024

    In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-197228210

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-39675

    Last Modified: 21 Nov 2024

    In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-205729183

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39674

    Last Modified: 21 Nov 2024

    In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39669

    Last Modified: 21 Nov 2024

    In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-196969991

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2021-39671

    Last Modified: 21 Nov 2024

    In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-206718630

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39668

    Last Modified: 21 Nov 2024

    In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-193445603

    Published: 11 Feb 2022
    5.5
    Medium

    CVE-2021-39666

    Last Modified: 21 Nov 2024

    In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-204445255

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2021-39665

    Last Modified: 21 Nov 2024

    In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-204077881

    Published: 11 Feb 2022
    5.5
    Medium

    CVE-2021-39664

    Last Modified: 21 Nov 2024

    In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure when parsing an APK file with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-203938029

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39663

    Last Modified: 21 Nov 2024

    In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-200682135

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39662

    Last Modified: 21 Nov 2024

    In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider collections due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-197302116

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-39658

    Last Modified: 21 Nov 2024

    ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system properties。Product: AndroidVersions: Android SoCAndroid ID: A-207479207

    Published: 11 Feb 2022
    9.1
    Critical

    CVE-2021-39635

    Last Modified: 21 Nov 2024

    ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634

    Published: 11 Feb 2022
    5.5
    Medium

    CVE-2021-39631

    Last Modified: 21 Nov 2024

    In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wrong security/privacy expectations due to a misleading message. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-193890833

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-39616

    Last Modified: 21 Nov 2024

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-39619

    Last Modified: 21 Nov 2024

    In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-197399948

    Published: 11 Feb 2022
    7.8
    High

    CVE-2022-0483

    Last Modified: 21 Nov 2024

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22824

    Last Modified: 21 Nov 2024

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)

    Published: 11 Feb 2022
    9.1
    Critical

    CVE-2021-22823

    Last Modified: 21 Nov 2024

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22800

    Last Modified: 21 Nov 2024

    A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP. Affected Product: Modicon M218 Logic Controller (V5.1.0.6 and prior)

    Published: 11 Feb 2022
    9.1
    Critical

    CVE-2021-22805

    Last Modified: 21 Nov 2024

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22804

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-22802

    Last Modified: 21 Nov 2024

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-22803

    Last Modified: 21 Nov 2024

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-22801

    Last Modified: 21 Nov 2024

    A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with specially crafted event actions. Affected Product: ConneXium Network Manager Software (All Versions)

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22806

    Last Modified: 21 Nov 2024

    A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22788

    Last Modified: 29 May 2026

    A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22798

    Last Modified: 21 Nov 2024

    A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext� ComBox (All Versions)

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22787

    Last Modified: 29 May 2026

    A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-22785

    Last Modified: 29 May 2026

    A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-22796

    Last Modified: 21 Nov 2024

    A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

    Published: 11 Feb 2022
    8.3
    High

    CVE-2020-14523

    Last Modified: 16 Apr 2025

    Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2021-22748

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

    Published: 11 Feb 2022
    8.3
    High

    CVE-2020-14521

    Last Modified: 16 Apr 2025

    Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

    Published: 11 Feb 2022
    5.7
    Medium

    CVE-2022-24926

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.

    Published: 11 Feb 2022
    4.2
    Medium

    CVE-2022-24927

    Last Modified: 21 Nov 2024

    Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.

    Published: 11 Feb 2022
    4.4
    Medium

    CVE-2022-24925

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.

    Published: 11 Feb 2022
    2.2
    Low

    CVE-2022-24924

    Last Modified: 21 Nov 2024

    An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

    Published: 11 Feb 2022
    4
    Medium

    CVE-2022-24003

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent.

    Published: 11 Feb 2022
    4
    Medium

    CVE-2022-24923

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

    Published: 11 Feb 2022
    4
    Medium

    CVE-2022-24002

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.

    Published: 11 Feb 2022
    3.8
    Low

    CVE-2022-24001

    Last Modified: 21 Nov 2024

    Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.

    Published: 11 Feb 2022
    3.9
    Low

    CVE-2022-23999

    Last Modified: 21 Nov 2024

    PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

    Published: 11 Feb 2022
    3.9
    Low

    CVE-2022-24000

    Last Modified: 21 Nov 2024

    PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

    Published: 11 Feb 2022
    6.2
    Medium

    CVE-2022-23998

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.

    Published: 11 Feb 2022
    4
    Medium

    CVE-2022-23997

    Last Modified: 21 Nov 2024

    Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission.

    Published: 11 Feb 2022
    4
    Medium

    CVE-2022-23996

    Last Modified: 21 Nov 2024

    Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.

    Published: 11 Feb 2022