Show filters
542 Total Results
Displaying 31-40 of 542
Sort by:
Attacker Value
Unknown
CVE-2021-40853
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to obtain sensible information.
0
Attacker Value
Unknown
CVE-2021-44857
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit rights for). This applies to any public wiki, or a private wiki that has at least one page set in $wgWhitelistRead.
0
Attacker Value
Unknown
CVE-2021-39651
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In TBD of TBD, there is a possible way to access PIN protected settings bypassing PIN confirmation due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-193438173References: N/A
0
Attacker Value
Unknown
CVE-2021-39639
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198291476References: N/A
0
Attacker Value
Unknown
CVE-2021-1034
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In getLine1NumberForDisplay of PhoneInterfaceManager.java, there is apossible way to determine whether an app is installed, without querypermissions due to a missing permission check. This could lead to localinformation disclosure with no additional execution privileges needed. Userinteraction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193441322
0
Attacker Value
Unknown
CVE-2021-1025
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193800652
0
Attacker Value
Unknown
CVE-2021-1017
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-182583850
0
Attacker Value
Unknown
CVE-2021-1011
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In setPackageStoppedState of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-188219307
0
Attacker Value
Unknown
CVE-2021-1010
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-189857801
0
Attacker Value
Unknown
CVE-2021-1004
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197749180
0