2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39790 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could... |
| CVE-2021-39789 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local esca... |
| CVE-2021-39788 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the dev... |
| CVE-2021-39787 | HIGH | 7.8 | 0.4% | Mar 30, 2022 | In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation... |
| CVE-2021-39786 | MEDIUM | 6.7 | 0.1% | Mar 30, 2022 | In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2021-39784 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission chec... |
| CVE-2021-39783 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local es... |
| CVE-2021-39782 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This... |
| CVE-2021-39781 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escal... |
| CVE-2021-39780 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing p... |
| CVE-2021-39779 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local informatio... |
| CVE-2021-39778 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to imprope... |
| CVE-2021-39777 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a miss... |
| CVE-2021-39776 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ... |
| CVE-2021-39775 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In People, there is a possible way to determine whether an app is installed, without query permissions, due to side chan... |
| CVE-2021-39774 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s... |
| CVE-2021-39773 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosur... |
| CVE-2021-39772 | HIGH | 8.8 | 0.2% | Mar 30, 2022 | In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This co... |
| CVE-2021-39771 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validat... |
| CVE-2021-39770 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could l... |
| CVE-2021-39769 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a ... |
| CVE-2021-39768 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing per... |
| CVE-2021-39767 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default va... |
| CVE-2021-39766 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch... |
| CVE-2021-39765 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclos... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now