2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39708CRITICAL9.8In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. Th...
CVE-2021-39707HIGH7.8In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a...
CVE-2021-39706HIGH7.8In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missin...
CVE-2021-39705Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-39704HIGH7.8In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service ...
CVE-2021-39703HIGH7.8In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This...
CVE-2021-39702HIGH7.8In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates with...
CVE-2021-39701HIGH7.8In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foregrou...
CVE-2021-39698HIGH7.8In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to lo...
CVE-2021-39697HIGH7.8In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private director...
CVE-2021-39695HIGH7.8In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This c...
CVE-2021-39694HIGH7.8In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user d...
CVE-2021-39693HIGH7.8In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due t...
CVE-2021-39692HIGH7.8In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a...
CVE-2021-39690MEDIUM5.5In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper ...
CVE-2021-39689MEDIUM6.7In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the c...
CVE-2021-39686HIGH7In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race conditi...
CVE-2021-39685HIGH7.8In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag c...
CVE-2021-39667MEDIUM6.5In ih264d_parse_decode_slice of ih264d_parse_slice.c, there is a possible out of bounds write due to a heap buffer overf...
CVE-2021-39624MEDIUM5.5In PackageManager, there is a possible permanent denial of service due to resource exhaustion. This could lead to local ...
CVE-2021-33853MEDIUM5.4A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser i...
CVE-2021-23165CRITICAL9.8A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to ...
CVE-2021-23158CRITICAL9.8A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-...
CVE-2021-20299HIGH7.5A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts c...
CVE-2021-20257MEDIUM6.5An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx)...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now