LiveActive security incident?Get immediate response
CVE archive

June 2021

Browse CVE records published in June 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1730 matching CVEs · Page 33 of 35.

High · CVSS 8.3

CVE-2021-1073: NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a us...

NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other web page is loaded in other tabs of the same browser. In this situation, the web page can get access to the token of the user login session, leading to the possibility that the user’s account is compromised. This may lead to the targeted user’s data being accessed, altered, or lost.

Published Jun 25, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0608: In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confus...

In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174870704

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0570: In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to...

In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178803845

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0607: In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data d...

In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-180950209

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0606: In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting.

In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168034487

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0571: In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService...

In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137395936

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0572: In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe Pen...

In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-177931355

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0561: In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a...

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0547: In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value t...

In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in some HAL implementations with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174151048

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0568: In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a...

In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170121238

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0541: In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due t...

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0552: In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe P...

In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-175124820

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0553: In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due t...

In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169936038

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0558: In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer o...

In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173473906

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0567: In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass.

In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179461812

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0562: In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds c...

In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176084648

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0563: In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap...

In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172908358

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0549: In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to...

In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183961896

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0566: In accessAudioHalPidscpp of TimeCheck.cpp, there is a possible out of bounds read due to a missing bounds c...

In accessAudioHalPidscpp of TimeCheck.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-175894436

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0548: In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check.

In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157650357

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0544: In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing...

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169257710

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0550: In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permission...

In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without user consent due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179688673

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0545: In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing...

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258884

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0546: In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing...

In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258733

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode du...

In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178821491

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0537: In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration...

In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176756141

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0543: In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to an int...

In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258743

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0551: In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media...

In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-180518039

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0536: In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused...

In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176756691

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0540: In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bound...

In halWrapperDataCallback of hal_wrapper.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169328517

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0539: In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation wi...

In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-180419673

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0517: In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determinatio...

In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179053823

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0513: In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible...

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-156090809

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0516: In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use aft...

In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181660448

Published Jun 21, 2021 · Updated Aug 3, 2024