2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39790HIGH7.8In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could...
CVE-2021-39789HIGH7.8In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local esca...
CVE-2021-39788MEDIUM5.5In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the dev...
CVE-2021-39787HIGH7.8In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation...
CVE-2021-39786MEDIUM6.7In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2021-39784HIGH7.8In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission chec...
CVE-2021-39783HIGH7.8In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local es...
CVE-2021-39782HIGH7.8In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This...
CVE-2021-39781HIGH7.8In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escal...
CVE-2021-39780HIGH7.8In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing p...
CVE-2021-39779MEDIUM5.5In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local informatio...
CVE-2021-39778MEDIUM5.5In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to imprope...
CVE-2021-39777MEDIUM5.5In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a miss...
CVE-2021-39776HIGH7.8In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ...
CVE-2021-39775MEDIUM5.5In People, there is a possible way to determine whether an app is installed, without query permissions, due to side chan...
CVE-2021-39774MEDIUM5.5In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s...
CVE-2021-39773MEDIUM5.5In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosur...
CVE-2021-39772HIGH8.8In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This co...
CVE-2021-39771HIGH7.8In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validat...
CVE-2021-39770MEDIUM5.5In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could l...
CVE-2021-39769MEDIUM5.5In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a ...
CVE-2021-39768HIGH7.8In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing per...
CVE-2021-39767HIGH7.8In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default va...
CVE-2021-39766MEDIUM5.5In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch...
CVE-2021-39765MEDIUM5.5In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclos...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now