CVE-2021-0 to CVE-2021-999
66 CVEs with public proof-of-concept exploits.
- CVE-2021-00892 PoCsObservable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via…
- CVE-2021-01571 PoCInsufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable…
- CVE-2021-01581 PoCImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation…
- CVE-2021-01861 PoCImproper input validation in the Intel(R) SGX SDK applications compiled for SGX2 enabled processors may allow a privileged user to…
- CVE-2021-02521 PoCJunos OS: NFX Series: Local Code Execution Vulnerability in JDMD Leads to Privilege Escalation
- CVE-2021-02531 PoCJunos OS: NFX Series: Local Command Execution Vulnerability in JDMD Leads to Privilege Escalation
- CVE-2021-03021 PoCIn PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of…
- CVE-2021-03071 PoCIn updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a…
- CVE-2021-03081 PoCIn ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local…
- CVE-2021-03131 PoCIn isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could…
- CVE-2021-03152 PoCsIn onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account…
- CVE-2021-03161 PoCIn avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to…
- CVE-2021-03181 PoCIn appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-free. This could…
- CVE-2021-03191 PoCIn checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address…
- CVE-2021-03251 PoCIn ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to…
- CVE-2021-03265 PoCsIn p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code…
- CVE-2021-03281 PoCIn onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without…
- CVE-2021-03291 PoCIn several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This…
- CVE-2021-03301 PoCIn add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local…
- CVE-2021-03311 PoCIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This…
- CVE-2021-03321 PoCIn bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation…
- CVE-2021-03331 PoCIn onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the…
- CVE-2021-03342 PoCsIn onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for…
- CVE-2021-03361 PoCIn onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to…
- CVE-2021-03371 PoCIn moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local…
- CVE-2021-03402 PoCsIn parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This…
- CVE-2021-03901 PoCIn various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing…
- CVE-2021-03921 PoCIn main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with…
- CVE-2021-03931 PoCIn Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow. This could lead…
- CVE-2021-03941 PoCIn android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This…
- CVE-2021-03961 PoCIn Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an…
- CVE-2021-03971 PoCIn sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code…
- CVE-2021-03991 PoCIn qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of…
- CVE-2021-04312 PoCsIn avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote…
- CVE-2021-04331 PoCIn onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth device due to a…
- CVE-2021-04342 PoCsIn onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire…
- CVE-2021-04352 PoCsIn avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote…
- CVE-2021-04371 PoCIn setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged…
- CVE-2021-04661 PoCIn startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote…
- CVE-2021-04742 PoCsIn avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code…
- CVE-2021-04751 PoCIn on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code…
- CVE-2021-04761 PoCIn FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of…
- CVE-2021-04781 PoCIn updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local…
- CVE-2021-04811 PoCIn onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler.…
- CVE-2021-04851 PoCIn getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions…
- CVE-2021-05061 PoCIn ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could…
- CVE-2021-05071 PoCIn handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote…
- CVE-2021-05081 PoCIn various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of…
- CVE-2021-05091 PoCIn various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation…
- CVE-2021-05101 PoCIn decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local…
- CVE-2021-05111 PoCIn Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to…
- CVE-2021-05161 PoCIn p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to…
- CVE-2021-05191 PoCIn BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local…
- CVE-2021-05202 PoCsIn several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could…
- CVE-2021-05221 PoCIn ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to…
- CVE-2021-05861 PoCIn onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a…
- CVE-2021-05893 PoCsIn BTM_TryAllocateSCN of btm_scn.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local…
- CVE-2021-05941 PoCIn onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead…
- CVE-2021-05951 PoCIn lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after…
- CVE-2021-06001 PoCIn onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input…
- CVE-2021-06392 PoCsIn multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive…
- CVE-2021-06401 PoCIn noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local…
- CVE-2021-06521 PoCIn VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not…
- CVE-2021-06881 PoCIn lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation…
- CVE-2021-07052 PoCsIn sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted…
- CVE-2021-09631 PoCIn onCreate of KeyChainActivity.java, there is a possible way to use an app certificate stored in keychain due to a tapjacking/overlay…