2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0953 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmar... |
| CVE-2021-0952 | MEDIUM | 5 | 0.1% | Dec 15, 2021 | In doCropPhoto of PhotoSelectionHandler.java, there is a possible permission bypass due to a confused deputy. This could... |
| CVE-2021-0933 | HIGH | 8 | 0.4% | Dec 15, 2021 | In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to inte... |
| CVE-2021-0932 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent... |
| CVE-2021-0931 | MEDIUM | 5.5 | 0.1% | Dec 15, 2021 | In getAlias of BluetoothDevice.java, there is a possible way to create misleading permission dialogs due to missing data... |
| CVE-2021-0930 | HIGH | 8.8 | 0.5% | Dec 15, 2021 | In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds ch... |
| CVE-2021-0929 | HIGH | 7.8 | 0.2% | Dec 15, 2021 | In ion_dma_buf_end_cpu_access and related functions of ion.c, there is a possible way to corrupt memory due to a use aft... |
| CVE-2021-0928 | HIGH | 7.8 | 0.4% | Dec 15, 2021 | In createFromParcel of OutputConfiguration.java, there is a possible parcel serialization/deserialization mismatch due t... |
| CVE-2021-0927 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due to a logic error in ... |
| CVE-2021-0926 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In onCreate of NfcImportVCardActivity.java, there is a possible way to add a contact without user's consent due to a mis... |
| CVE-2021-0925 | HIGH | 7.5 | 1.0% | Dec 15, 2021 | In rw_t4t_sm_detect_ndef of rw_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This cou... |
| CVE-2021-0924 | HIGH | 7.8 | 0.2% | Dec 15, 2021 | In xhci_vendor_get_ops of xhci.c, there is a possible out of bounds read due to a missing bounds check. This could lead ... |
| CVE-2021-0923 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In createOrUpdate of Permission.java, there is a possible way to gain internal permissions due to a missing permission c... |
| CVE-2021-0922 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROF... |
| CVE-2021-0921 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due ... |
| CVE-2021-0920 | MEDIUM | 6.4 | 0.8% | Dec 15, 2021 | In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to loca... |
| CVE-2021-0919 | MEDIUM | 5 | 0.1% | Dec 15, 2021 | In getService of IServiceManager.cpp, there is a possible unhandled exception due to an integer overflow. This could lea... |
| CVE-2021-0918 | HIGH | 8.8 | 0.4% | Dec 15, 2021 | In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This ... |
| CVE-2021-0904 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escala... |
| CVE-2021-0889 | CRITICAL | 9.8 | 1.6% | Dec 15, 2021 | In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to ... |
| CVE-2021-0799 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local ... |
| CVE-2021-0769 | HIGH | 7.3 | 0.1% | Dec 15, 2021 | In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to uncle... |
| CVE-2021-0704 | MEDIUM | 5.5 | 0.1% | Dec 15, 2021 | In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible wa... |
| CVE-2021-0675 | HIGH | 7.8 | 0.5% | Dec 15, 2021 | In alac decoder, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esca... |
| CVE-2021-0653 | MEDIUM | 5.5 | 0.1% | Dec 15, 2021 | In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a trackable identifier d... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now