2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0456 | MEDIUM | 6.7 | 0.1% | Mar 10, 2021 | In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to ... |
| CVE-2021-0455 | MEDIUM | 6.7 | 0.1% | Mar 10, 2021 | In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to ... |
| CVE-2021-0454 | MEDIUM | 6.7 | 0.1% | Mar 10, 2021 | In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to ... |
| CVE-2021-0453 | MEDIUM | 4.4 | 0.1% | Mar 10, 2021 | In the Titan-M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ... |
| CVE-2021-0452 | MEDIUM | 4.4 | 0.1% | Mar 10, 2021 | In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ... |
| CVE-2021-0451 | MEDIUM | 4.4 | 0.1% | Mar 10, 2021 | In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ... |
| CVE-2021-0450 | MEDIUM | 4.4 | 0.1% | Mar 10, 2021 | In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ... |
| CVE-2021-0449 | MEDIUM | 4.4 | 0.1% | Mar 10, 2021 | In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ... |
| CVE-2021-0389 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local esc... |
| CVE-2021-0388 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast... |
| CVE-2021-0387 | MEDIUM | 6.4 | 0.1% | Mar 10, 2021 | In FindQuotaDeviceForUuid of QuotaUtils.cpp, there is a possible use-after-free due to a race condition. This could lead... |
| CVE-2021-0386 | HIGH | 7.8 | 0.3% | Mar 10, 2021 | In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could le... |
| CVE-2021-0385 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connecti... |
| CVE-2021-0384 | — | — | — | Mar 10, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-0383 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In done of CaptivePortalLoginActivity.java, there is a confused deputy. This could lead to local escalation of privilege... |
| CVE-2021-0382 | MEDIUM | 5.5 | 0.1% | Mar 10, 2021 | In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permissio... |
| CVE-2021-0381 | MEDIUM | 5.5 | 0.1% | Mar 10, 2021 | In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe Pendi... |
| CVE-2021-0380 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony setting... |
| CVE-2021-0379 | MEDIUM | 6.5 | 0.8% | Mar 10, 2021 | In getUpTo17bits of pvmp3_getbits.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could ... |
| CVE-2021-24030 | CRITICAL | 9.8 | 1.7% | Mar 10, 2021 | The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the exe... |
| CVE-2021-24025 | CRITICAL | 9.8 | 1.7% | Mar 10, 2021 | Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function ca... |
| CVE-2021-20265 | MEDIUM | 5.5 | 0.3% | Mar 10, 2021 | A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a s... |
| CVE-2021-0399 | HIGH | 7.8 | 0.4% | Mar 10, 2021 | In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to loca... |
| CVE-2021-0398 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. Thi... |
| CVE-2021-0397 | CRITICAL | 9.8 | 5.7% | Mar 10, 2021 | In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now