LiveActive security incident?Get immediate response
CVE archive

June 2021

Browse CVE records published in June 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1730 matching CVEs · Page 34 of 35.

Unknown · CVSS Not scored

CVE-2021-0504: In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds...

In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179162665

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0510: In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow.

In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444622

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0472: In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN...

In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-176801033

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0506: In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjac...

In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-181962311

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0520: In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a...

In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-176237595

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0534: In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection du...

In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170639543

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0511: In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input vali...

In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-178055795

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0467: In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check.

In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the bootloader, with physical USB access, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-174490700

Published Jun 14, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0522: In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use a...

In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-174182139

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0484: In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bou...

In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-173720767

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0481: In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due t...

In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-172939189

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0523: In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user con...

In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-174047492

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0521: In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing per...

In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of cross-user permissions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174661955

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0535: In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use aft...

In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741

Published Jun 22, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0507: In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check.

In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181860042

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0512: In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to...

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0485: In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background proc...

In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302616

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0508: In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition.

In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-176444154

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0480: In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive id...

In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-174493336

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0466: In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device.

In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This could lead to remote information disclosure to a proximal attacker, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-154114734

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0491: In memory management driver, there is a possible escalation of privilege due to a missing permission check.

In memory management driver, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-183461315

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0505: In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check.

In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179975048

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0474: In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow.

In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-177611958

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0477: In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass d...

In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-178189250

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0475: In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free.

In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-175686168

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0487: In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard wi...

In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174046397

Published Jun 11, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0509: In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition.

In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444161

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0478: In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught excep...

In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This could lead to local escalation of privilege by running foreground services without notifying the user, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-169255797

Published Jun 21, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-0473: In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data.

In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-179687208

Published Jun 11, 2021 · Updated Aug 3, 2024