CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2021-39643

    Last Modified: 21 Nov 2024

    In ic_startRetrieveEntryValue of acropora/app/identity/ic.c, there is a possible bypass of defense-in-depth due to missing validation of the return value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195573629References: N/A

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1012

    Last Modified: 21 Nov 2024

    In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195412179

    Published: 15 Dec 2021
    7.3
    High

    CVE-2021-1020

    Last Modified: 21 Nov 2024

    In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195111725

    Published: 15 Dec 2021
    7.3
    High

    CVE-2021-1021

    Last Modified: 21 Nov 2024

    In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195031703

    Published: 15 Dec 2021
    7.3
    High

    CVE-2021-1019

    Last Modified: 21 Nov 2024

    In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195031401

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1026

    Last Modified: 21 Nov 2024

    In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194798757

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-1031

    Last Modified: 21 Nov 2024

    In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194697004

    Published: 15 Dec 2021
    4.4
    Medium

    CVE-2021-39657

    Last Modified: 21 Nov 2024

    In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1030

    Last Modified: 21 Nov 2024

    In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194697001

    Published: 15 Dec 2021
    7.5
    High

    CVE-2021-1002

    Last Modified: 21 Nov 2024

    In WT_Interpolate of eas_wtengine.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194533433

    Published: 15 Dec 2021
    6.7
    Medium

    CVE-2021-39652

    Last Modified: 21 Nov 2024

    In sec_ts_parsing_cmds of (TBD), there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194499021References: N/A

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0989

    Last Modified: 21 Nov 2024

    In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194105812

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-1018

    Last Modified: 21 Nov 2024

    In adjustStreamVolume of AudioService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194110891

    Published: 15 Dec 2021
    6.5
    Medium

    CVE-2021-0993

    Last Modified: 21 Nov 2024

    In getOffsetBeforeAfter of TextLine.java, there is a possible denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193849901

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0994

    Last Modified: 21 Nov 2024

    In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193801134

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1025

    Last Modified: 21 Nov 2024

    In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193800652

    Published: 15 Dec 2021
    4.4
    Medium

    CVE-2021-39637

    Last Modified: 21 Nov 2024

    In CreateDeviceInfo of trusty_remote_provisioning_context.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-193579873References: N/A

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-39653

    Last Modified: 21 Nov 2024

    In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalation of privilege after preparing the device, hiding the warning, and passing the phone to a new user, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-193443223References: N/A

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-0998

    Last Modified: 21 Nov 2024

    In 'ih264e_find_bskip_params()' of ih264e_me.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193442575

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-1034

    Last Modified: 21 Nov 2024

    In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is installed, without querypermissions due to a missing permission check. This could lead to localinformation disclosure with no additional execution privileges needed. Userinteraction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193441322

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-39651

    Last Modified: 21 Nov 2024

    In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-193438173References: N/A

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-1028

    Last Modified: 21 Nov 2024

    In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193034683

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-1029

    Last Modified: 21 Nov 2024

    In setClientStateLocked of SurfaceFlinger.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193034677

    Published: 15 Dec 2021
    9.8
    Critical

    CVE-2021-39655

    Last Modified: 21 Nov 2024

    Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-1027

    Last Modified: 21 Nov 2024

    In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193033243

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0978

    Last Modified: 21 Nov 2024

    In getSerialForPackage of DeviceIdentifiersPolicyService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192587406

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-0984

    Last Modified: 21 Nov 2024

    In onNullBinding of ManagedServices.java, there is a possible permission bypass due to an incorrectly unbound service. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192475653

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0982

    Last Modified: 21 Nov 2024

    In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization name disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192368508

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-0986

    Last Modified: 21 Nov 2024

    In hasGrantedPolicy of DevicePolicyManagerService.java, there is a possible information disclosure about the device owner, profile owner, or device admin due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192247339

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0983

    Last Modified: 21 Nov 2024

    In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-192245204

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-0981

    Last Modified: 21 Nov 2024

    In enqueueNotificationInternal of NotificationManagerService.java, there is a possible way to run a foreground service without showing a notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-191981182

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0988

    Last Modified: 21 Nov 2024

    In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191954233

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-0979

    Last Modified: 21 Nov 2024

    In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191772737

    Published: 15 Dec 2021
    6.7
    Medium

    CVE-2021-1024

    Last Modified: 21 Nov 2024

    In onEventReceived of EventResultPersister.java, there is a possible intent redirection due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191283525

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0987

    Last Modified: 21 Nov 2024

    In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-190619791

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-0997

    Last Modified: 21 Nov 2024

    In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191086488

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1001

    Last Modified: 21 Nov 2024

    In PVInitVideoEncoder of mp4enc_api.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-190435883

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-0985

    Last Modified: 21 Nov 2024

    In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-190403923

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1009

    Last Modified: 21 Nov 2024

    In setApplicationCategoryHint of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189858128

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1010

    Last Modified: 21 Nov 2024

    In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189857801

    Published: 15 Dec 2021
    7.8
    High

    CVE-2021-1003

    Last Modified: 21 Nov 2024

    In adjustStreamVolume of AudioService.java, there is a possible way for unprivileged app to change audio stream volume due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189857506

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1014

    Last Modified: 21 Nov 2024

    In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186776740

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1011

    Last Modified: 21 Nov 2024

    In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-188219307

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1005

    Last Modified: 21 Nov 2024

    In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186530889

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-1015

    Last Modified: 21 Nov 2024

    In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186530496

    Published: 15 Dec 2021
    5.5
    Medium

    CVE-2021-1013

    Last Modified: 21 Nov 2024

    In checkExistsAndEnforceCannotModifyImmutablyRestrictedPermission of PermissionManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-186404356

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-0990

    Last Modified: 21 Nov 2024

    In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-185591180

    Published: 15 Dec 2021
    3.3
    Low

    CVE-2021-1032

    Last Modified: 21 Nov 2024

    In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-184745603

    Published: 15 Dec 2021
    7.3
    High

    CVE-2021-0769

    Last Modified: 21 Nov 2024

    In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to unclear UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-184676316

    Published: 15 Dec 2021
    4.4
    Medium

    CVE-2021-1006

    Last Modified: 21 Nov 2024

    In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-183961974

    Published: 15 Dec 2021