LiveActive security incident?Get immediate response
CVE archive

April 2021

Browse CVE records published in April 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2026 matching CVEs · Page 19 of 41.

Unknown · CVSS Not scored

CVE-2021-42324: An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470.

An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.

Published Apr 5, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-42136: A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before...

A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.

Published Apr 13, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-42029: A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA...

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-40374: A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1.

A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes when the patient profile is loaded, which could be used in a XSS attack.

Published Apr 6, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-40375: Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients wit...

Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. This response can be read in an intercepting proxy or by viewing the page source. Sensitive information returned in responses includes patient PII and medication records or history.

Published Apr 6, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39808: In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run i...

In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209966086

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39800: In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free.

In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-208277166References: Upstream kernel

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39804: In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check.

In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215002587

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39799: In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input...

In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-200288596

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39796: In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to...

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39805: In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check.

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-212694559

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39803: In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free.

In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-193790350

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39814: In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check.

In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216792660References: N/A

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39809: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bo...

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205837191

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39807: In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest acc...

In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-209446496

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39802: In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permiss...

In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213339151References: Upstream kernel

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39797: In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic er...

In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-209607104

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39798: In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bou...

In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213169612

Published Apr 12, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-39794: In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if...

In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-205836329

Published Apr 12, 2022 · Updated Aug 4, 2024