Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.3
CVE-2021-0598

In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could…

Patch available
Fix from $1,950 2021-10-06
Android HIGH 7.0
CVE-2021-0688

In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privile…

Patch available
Fix from $1,950 2021-10-06
Android MEDIUM 5.5
CVE-2021-0644

In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permiss…

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0680

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0681

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure w…

Mitigation only
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0682

In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. …

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0686

In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user d…

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0689

In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat…

Patch available
Fix from $1,600 2021-10-06
Android MEDIUM 5.0
CVE-2021-0687

In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional …

Patch available
Fix from $1,600 2021-10-06
Slo Generator HIGH 7.8
CVE-2021-22557

SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera…

Fix: 2.0.1+
Fix from $1,950 2021-10-04
Android HIGH 7.8
CVE-2021-23243

In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used.

No fix yet
Fix from $1,950 2021-09-27
Android HIGH 7.8
CVE-2021-0610

In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2021-09-27
Android HIGH 7.8
CVE-2021-0611

In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile…

Mitigation only
Fix from $1,950 2021-09-27
Android HIGH 7.8
CVE-2021-0612

In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privile…

Mitigation only
Fix from $1,950 2021-09-27
Android MEDIUM 5.5
CVE-2021-0421

In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosur…

Mitigation only
Fix from $1,600 2021-09-27
Android MEDIUM 5.5
CVE-2021-0422

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit…

Mitigation only
Fix from $1,600 2021-09-27
Android MEDIUM 5.5
CVE-2021-0423

In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure wi…

Mitigation only
Fix from $1,600 2021-09-27
Android MEDIUM 5.5
CVE-2021-0424

In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with no addit…

Mitigation only
Fix from $1,600 2021-09-27
Android MEDIUM 5.5
CVE-2021-0425

In memory management driver, there is a possible side channel information disclosure. This could lead to local information disclosure with no additio…

Mitigation only
Fix from $1,600 2021-09-27
Android CRITICAL 9.8
CVE-2021-0869

In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote cod…

Mitigation only
Fix from $2,300 2021-09-21
Android HIGH 7.8
CVE-2021-25461

An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

Mitigation only
Fix from $1,950 2021-09-09
Android MEDIUM 5.5
CVE-2021-25462

NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25453

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25454

OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25456

OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via for…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25458

NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25459

An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZSe…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25460

An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate Blockchain…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 6.5
CVE-2021-25450

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socke…

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25452

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent …

Mitigation only
Fix from $1,600 2021-09-09