Security
Headlines
HeadlinesLatestCVEs

Tag

#android

BQE Web Suite Billing App Rigged to Inflict Ransomware

An SQL-injection bug in the BQE Web Suite billing app has not only leaked sensitive information, it’s also let malicious actors execute code and deploy ransomware.

Threatpost
#Cloud Security#InfoSec Insider#Vulnerabilities#vulnerability#Breach#Web Security#Sponsored#Vulnerabilities#Malware#Web Security#microsoft#Malware#Web Security#Malware#Mobile Security#Web Security#android#Cloud Security#Critical Infrastructure#InfoSec Insider#Mobile Security#Vulnerabilities#Web Security#Malware#Web Security#Hacks#Malware#Vulnerabilities#Web Security#sql#web
CVE-2021-0938: Pixel Update Bulletin—October 2021  |  Android Open Source Project

In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-171418586References: Upstream kernel

CVE-2021-0941: Pixel Update Bulletin—October 2021  |  Android Open Source Project

In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154177719References: Upstream kernel

CVE-2021-0939: Pixel Update Bulletin—October 2021  |  Android Open Source Project

In set_default_passthru_cfg of passthru.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-186026549References: N/A

CVE-2021-0936: Pixel Update Bulletin—October 2021  |  Android Open Source Project

In acc_read of f_accessory.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173789633References: Upstream kernel

CVE-2021-0940: Pixel Update Bulletin—October 2021  |  Android Open Source Project

In TBD of TBD, there is a possible out of bounds write due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-171315276References: N/A

CVE-2021-0935: Pixel Update Bulletin—October 2021  |  Android Open Source Project

In ip6_xmit of ip6_output.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168607263References: Upstream kernel

CVE-2021-0705: Android Security Bulletin—October 2021  |  Android Open Source Project

In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-185388103

CVE-2021-0702: Android Security Bulletin—October 2021  |  Android Open Source Project

In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore downgrade. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-193932765

CVE-2021-0643: Android Security Bulletin—October 2021  |  Android Open Source Project

In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-183612370