CVE-2021-41773
CVEs:CVE-2021-41773
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 17 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
CVEs:CVE-2021-41773
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories ...
CVEs:CVE-2021-41773
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cloud_backup | affected | netapp | — | — |
| fedora | affected | fedoraproject | — | — |
| http_server | affected | apache | — | — |
| instantis_enterprisetrack | affected | oracle | — | — |
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office document...
CVEs:CVE-2021-40444
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_10_2004 | affected | microsoft | — | — |
| windows_10_20h2 | affected | microsoft | — | — |
| windows_10_21h1 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2004 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_20h2 | affected | microsoft | — | — |
CVEs:CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
CVEs:CVE-2021-40444
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.2 | chromium | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP3 | chromium | — |
| chromium | affected | openSUSE:Leap 15.3 | chromium | — |
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30632
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30632
CVEs:CVE-2021-30632
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-30633
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30633
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-30633
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-37973
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2021-37973
Confused Deputy in Kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Confused Deputy in Kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| nodetaint | affected | wolfi | nodetaint | — |
| nodetaint | affected | chainguard | nodetaint | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
DEBIAN-CVE-2020-8561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that ...
CVEs:CVE-2020-8561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
Confused Deputy in Kubernetes
CVEs:CVE-2020-8561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Confused Deputy in Kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubeflow-pipelines | affected | wolfi | kubeflow-pipelines | — |
| kubeflow-pipelines | affected | chainguard | kubeflow-pipelines | — |
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
| kubernetes-1.28 | affected | wolfi | kubernetes-1.28 | — |
| kubernetes-1.28 | affected | chainguard | kubernetes-1.28 | — |
| kubernetes-1.29 | affected | chainguard | kubernetes-1.29 | — |
| kubernetes-1.29 | affected | wolfi | kubernetes-1.29 | — |
| kubernetes-1.30 | affected | wolfi | kubernetes-1.30 | — |
| kubernetes-1.30 | affected | chainguard | kubernetes-1.30 | — |
| kubernetes-1.31 | affected | wolfi | kubernetes-1.31 | — |
| kubernetes-1.31 | affected | chainguard | kubernetes-1.31 | — |
| kubernetes-1.32 | affected | wolfi | kubernetes-1.32 | — |
| kubernetes-1.32 | affected | chainguard | kubernetes-1.32 | — |
| kubernetes-dns-node-cache-1.17 | affected | chainguard | kubernetes-dns-node-cache-1.17 | — |
| nodetaint | affected | chainguard | nodetaint | — |
| nodetaint | affected | wolfi | nodetaint | — |
| spark-operator | affected | chainguard | spark-operator | — |
| spark-operator | affected | wolfi | spark-operator | — |
Confused Deputy in Kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
DEBIAN-CVE-2021-25740
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
DEBIAN-CVE-2021-25741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
Files or Directories Accessible to External Parties in kubernetes
CVEs:CVE-2021-25741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
CVEs:CVE-2021-25741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
kubernetes security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | openEuler:20.03-LTS-SP1 | kubernetes | — |
| kubernetes | affected | openEuler:20.03-LTS-SP2 | kubernetes | — |
DEBIAN-CVE-2021-25735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
Moderate: go-toolset:rhel8 security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
Updated golang packages fix security vulnerability
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Mageia:8 | golang | — |
Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-37972
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37972
Improper Authorization in Google OAuth Client
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.oauth-client:google-oauth-client | affected | Maven | com.google.oauth-client:google-oauth-client | — |
Improper Authorization in Google OAuth Client
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.google.oauth-client:google-oauth-client | affected | Maven | com.google.oauth-client:google-oauth-client | — |
Incomplete List of Disallowed Inputs in Kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
Incomplete List of Disallowed Inputs in Kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
DEBIAN-CVE-2021-25737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
Incomplete List of Disallowed Inputs in Kubernetes
CVEs:CVE-2021-25737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not per...
CVEs:CVE-2021-25737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
PUB-A-190877100
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
PUB-A-172378366
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2021-0683
In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2021-0683
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVEs:CVE-2021-0595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0595
CVEs:CVE-2021-25461
An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
CVEs:CVE-2021-25461
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: Andr...
CVEs:CVE-2021-0688
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0688
CVEs:CVE-2021-30625
Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30625
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30615
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
CVEs:CVE-2021-30615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30614
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
CVEs:CVE-2021-30614
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30609
Chromium: CVE-2021-30609 Use after free in Sign-In
CVEs:CVE-2021-30609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30616
Chromium: CVE-2021-30616 Use after free in Media
CVEs:CVE-2021-30616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Chromium: CVE-2021-30610 Use after free in Extensions API
CVEs:CVE-2021-30610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30610
DEBIAN-CVE-2021-30624
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
DEBIAN-CVE-2021-30613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30620
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Chromium: CVE-2021-30606 Use after free in Blink
CVEs:CVE-2021-30606
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30606
CVEs:CVE-2021-30607
Chromium: CVE-2021-30607 Use after free in Permissions
CVEs:CVE-2021-30607
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
Chromium: CVE-2021-30613 Use after free in Base internals
CVEs:CVE-2021-30613
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30613
CVEs:CVE-2021-30618
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
CVEs:CVE-2021-30618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30620
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
CVEs:CVE-2021-30620
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30624
Chromium: CVE-2021-30624 Use after free in Autofill
CVEs:CVE-2021-30624
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30622
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Chromium: CVE-2021-30608 Use after free in Web Share
CVEs:CVE-2021-30608
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30608
Chromium: CVE-2021-30622 Use after free in WebApp Installs
CVEs:CVE-2021-30622
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30622
DEBIAN-CVE-2021-30623
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
Chromium: CVE-2021-30623 Use after free in Bookmarks
CVEs:CVE-2021-30623
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30623
DEBIAN-CVE-2021-30617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30617
Chromium: CVE-2021-30617 Policy bypass in Blink
CVEs:CVE-2021-30617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2021-30621
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30619
Chromium: CVE-2021-30619 UI Spoofing in Autofill
CVEs:CVE-2021-30619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30621
Chromium: CVE-2021-30621 UI Spoofing in Autofill
CVEs:CVE-2021-30621
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-40448
Microsoft Accessibility Insights for Android Information Disclosure Vulnerability
CVEs:CVE-2021-40448
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| accessibility_insights_for_android | affected | microsoft | — | — |
CVEs:CVE-2021-38669
Microsoft Edge (Chromium-based) Tampering Vulnerability
CVEs:CVE-2021-38669
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
DEBIAN-CVE-2021-30611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30611
Chromium: CVE-2021-30611 Use after free in WebRTC
CVEs:CVE-2021-30611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
DEBIAN-CVE-2021-30612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2021-30612
Chromium: CVE-2021-30612 Use after free in WebRTC
CVEs:CVE-2021-30612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge | affected | microsoft | — | — |
| edge_chromium | affected | microsoft | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-40864
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
CVEs:CVE-2021-40864
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_translate | affected | onlyoffice | — | — |
CVEs:CVE-2021-37970
Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-37970
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-37961
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37961
CVEs:CVE-2021-37962
Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-37962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2021-37968
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37968
CVEs:CVE-2021-37971
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2021-37971
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37956
Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-37956
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37957
Use after free in WebGPU in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-37957
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2021-37965
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37965
Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVEs:CVE-2021-37963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37963
CVEs:CVE-2021-30626
Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30626
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
CVEs:CVE-2021-37958
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37958
CVEs:CVE-2021-30628
Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
CVEs:CVE-2021-30628
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37969
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
CVEs:CVE-2021-37969
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-37959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37959
Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30627
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30627
The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/morefromgoogle.php file which allows attackers to inject arbitrary web scripts, in versions up to and including...
CVEs:CVE-2021-38319
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| more_from_google | affected | windyroad | — | — |
CVEs:CVE-2021-38319
CVEs:CVE-2021-30629
Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2021-30629
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-0869
In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2021-0869
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-179620905
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed f...
CVEs:CVE-2021-0690
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0690
CVEs:CVE-2021-37967
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2021-37967
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2021-30630
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-30630
CVEs:CVE-2021-37966
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2021-37966
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via c...
CVEs:CVE-2021-40824
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| element | affected | matrix | — | — |
| matrix-android-sdk2 | affected | matrix | — | — |
Logic error in Matrix SDK for Android
CVEs:CVE-2021-40824
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.matrix.android:matrix-android-sdk2 | affected | Maven | org.matrix.android:matrix-android-sdk2 | — |
Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.
CVEs:CVE-2021-37964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2021-37964
CVEs:CVE-2021-0660
In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827145; Issue ID: ALPS05...
CVEs:CVE-2021-0660
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Improperly Implemented path matching for in-toto-golang
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| in-toto/in-toto-golang | affected | github.com | github.com/in-toto/in-toto-golang | — |
Improperly Implemented path matching for in-toto-golang
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| in-toto/in-toto-golang | affected | github.com | github.com/in-toto/in-toto-golang | — |
Improperly Implemented path matching for in-toto-golang
CVEs:CVE-2021-41087
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| in-toto/in-toto-golang | affected | github.com | github.com/in-toto/in-toto-golang | — |
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attest...
CVEs:CVE-2021-41087
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| in-toto-golang | affected | in-toto | — | — |
An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.
CVEs:CVE-2021-25449
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25449
CVEs:CVE-2021-0635
When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss o...
CVEs:CVE-2021-0635
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0636
When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss o...
CVEs:CVE-2021-0636
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-189392423
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-189402477
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-25456
OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.
CVEs:CVE-2021-25456
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25451
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
CVEs:CVE-2021-25451
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.
CVEs:CVE-2021-25454
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25454
In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2021-0685
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0685
OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
CVEs:CVE-2021-25455
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25455
CVEs:CVE-2021-25450
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.
CVEs:CVE-2021-25450
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
PUB-A-181677125
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
PUB-A-181677179
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-190404324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2021-0684
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0684
CVEs:CVE-2021-0598
In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is neede...
CVEs:CVE-2021-0598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0695
In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer...
CVEs:CVE-2021-0695
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-184018316
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel: | affected | Android | :linux_kernel: | — |
CVEs:CVE-2021-0687
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Andr...
CVEs:CVE-2021-0687
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-30605
Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects allowing an attacker to potentially bypass discretionary access controls.
CVEs:CVE-2021-30605
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome_os_readiness_tool | affected | — | — |
CVEs:CVE-2021-0689
In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2021-0689
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-190188264
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| external/skia | affected | platform | platform/external/skia | — |
CVEs:CVE-2021-25462
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
CVEs:CVE-2021-25462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25458
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
CVEs:CVE-2021-25458
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction...
CVEs:CVE-2021-0682
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0682
CVEs:CVE-2021-25452
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.
CVEs:CVE-2021-25452
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0610
In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A...
CVEs:CVE-2021-0610
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0611
In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS0542...
CVEs:CVE-2021-0611
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0612
In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS0542...
CVEs:CVE-2021-0612
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25459
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
CVEs:CVE-2021-25459
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patc...
CVEs:CVE-2021-0421
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0421
In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID...
CVEs:CVE-2021-0423
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0423
CVEs:CVE-2021-0425
In memory management driver, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0540349...
CVEs:CVE-2021-0425
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0644
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User ...
CVEs:CVE-2021-0644
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0693
In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User int...
CVEs:CVE-2021-0693
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution privi...
CVEs:CVE-2021-0691
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0691
CVEs:CVE-2021-0692
In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2021-0692
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.
CVEs:CVE-2021-23243
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-23243
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403...
CVEs:CVE-2021-0422
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0422
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403...
CVEs:CVE-2021-0424
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0424
CVEs:CVE-2021-0680
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2021-0680
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:...
CVEs:CVE-2021-0681
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0681
In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user due to a missing permission check. This could lead to local information disclosure with no additional ex...
CVEs:CVE-2021-0686
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-0686
ASB-A-192535337
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-192535676
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2021-25453
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
CVEs:CVE-2021-25453
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-190403706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
PUB-A-181676968
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
CVEs:CVE-2021-25457
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
CVEs:CVE-2021-25457
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
CVEs:CVE-2021-25460
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2021-25460
Invalid-free in generic specialization <Swift.Int> of Swift.Array.subscript.getter :
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| swift-protobuf | affected | OSS-Fuzz | swift-protobuf | — |
Invalid-free in swift_unexpectedError
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| swift-protobuf | affected | OSS-Fuzz | swift-protobuf | — |
Invalid-free in swift_unexpectedError
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| swift-protobuf | affected | OSS-Fuzz | swift-protobuf | — |
Invalid-free in swift_unexpectedError
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| swift-protobuf | affected | OSS-Fuzz | swift-protobuf | — |
Invalid-free in swift_unexpectedError
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| swift-protobuf | affected | OSS-Fuzz | swift-protobuf | — |
| swift-protobuf | affected | — | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.