Vulnerabilities (CVE)

Filtered by CWE-20
Total 11767 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25520 1 Samsung 1 Internet 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
CVE-2021-25517 1 Google 1 Android 2024-11-21 4.6 MEDIUM 7.7 HIGH
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.
CVE-2021-25512 1 Google 1 Android 2024-11-21 4.6 MEDIUM 6.1 MEDIUM
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.
CVE-2021-25511 1 Google 1 Android 2024-11-21 4.6 MEDIUM 6.3 MEDIUM
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.
CVE-2021-25510 1 Google 1 Android 2024-11-21 4.6 MEDIUM 5.3 MEDIUM
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.
CVE-2021-25509 1 Samsung 1 Samsung Flow 2024-11-21 3.6 LOW 5.9 MEDIUM
A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.
CVE-2021-25504 1 Samsung 1 Group Sharing 2024-11-21 2.1 LOW 4.0 MEDIUM
Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.
CVE-2021-25503 2 Google, Samsung 2 Android, Exynos 2024-11-21 4.6 MEDIUM 5.0 MEDIUM
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
CVE-2021-25500 2 Google, Samsung 5 Android, Exynos 2100, Exynos 980 and 2 more 2024-11-21 2.1 LOW 7.2 HIGH
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.
CVE-2021-25485 1 Google 1 Android 2024-11-21 5.8 MEDIUM 7.5 HIGH
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.
CVE-2021-25471 2 Google, Samsung 2 Android, Exynos 2024-11-21 5.0 MEDIUM 3.7 LOW
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.
CVE-2021-25468 2 Google, Samsung 2 Android, Exynos 2024-11-21 2.1 LOW 4.4 MEDIUM
A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.
CVE-2021-25465 1 Samsung 1 Themes 2024-11-21 4.4 MEDIUM 3.3 LOW
An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.
CVE-2021-25457 2 Google, Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2024-11-21 2.1 LOW 5.9 MEDIUM
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
CVE-2021-25453 1 Google 1 Android 2024-11-21 2.1 LOW 5.1 MEDIUM
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
CVE-2021-25452 2 Google, Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2024-11-21 4.9 MEDIUM 5.5 MEDIUM
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.
CVE-2021-25450 1 Google 1 Android 2024-11-21 3.3 LOW 4.5 MEDIUM
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.
CVE-2021-25444 1 Google 1 Android 2024-11-21 2.1 LOW 5.5 MEDIUM
An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
CVE-2021-25441 2 Google, Samsung 2 Android, Ar Emoji Editor 2024-11-21 4.6 MEDIUM 7.8 HIGH
Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applications to access arbitrary files with an escalated privilege.
CVE-2021-25437 1 Linux 1 Tizen 2024-11-21 10.0 HIGH 9.8 CRITICAL
Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers to arbitrary code execution by replacing FOTA update file.