
CVE-2021-0621
https://notcve.org/view.php?id=CVE-2021-0621
18 Nov 2021 — In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561383. En asf extractor, se presenta una posible lectura fuera de límites debido a un desbordamiento de enteros. • https://corp.mediatek.com/product-security-bulletin/November-2021 • CWE-190: Integer Overflow or Wraparound •

CVE-2021-0620
https://notcve.org/view.php?id=CVE-2021-0620
18 Nov 2021 — In asf extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561381. En asf extractor, se presenta una posible lectura fuera de límites debido a un desbordamiento del búfer de la pila. • https://corp.mediatek.com/product-security-bulletin/November-2021 • CWE-125: Out-of-bounds Read •

CVE-2021-0619
https://notcve.org/view.php?id=CVE-2021-0619
18 Nov 2021 — In ape extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05561395; Issue ID: ALPS05561395. En ape extractor, se presenta una posible lectura fuera de límites debido a la falta de comprobación de los límites. • https://corp.mediatek.com/product-security-bulletin/November-2021 • CWE-125: Out-of-bounds Read •

CVE-2021-0672
https://notcve.org/view.php?id=CVE-2021-0672
18 Nov 2021 — In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-199678035 En la aplicación Browser, existe una posible divulgación de información debido a la falta de comprobación de permisos. Esto podría conducir a la divulgación de información local sin necesidad de privilegios de eje... • https://source.android.com/security/bulletin/2021-11-01 • CWE-862: Missing Authorization •

CVE-2021-25503
https://notcve.org/view.php?id=CVE-2021-25503
05 Nov 2021 — Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution. Una vulnerabilidad de comprobación de entrada inapropiada en HDCP versiones anteriores a SMR Nov-2021 Release 1, permite a atacantes una ejecución de código arbitrario • https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=11 • CWE-20: Improper Input Validation •

CVE-2021-25502
https://notcve.org/view.php?id=CVE-2021-25502
05 Nov 2021 — A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge. Una vulnerabilidad de almacenamiento de información confidencial de forma no segura en Property Settings anterior a SMR Nov-2021 Release 1 permite a atacantes leer el valor de ESN sin privilegio • https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=11 • CWE-269: Improper Privilege Management CWE-312: Cleartext Storage of Sensitive Information •

CVE-2021-25501
https://notcve.org/view.php?id=CVE-2021-25501
05 Nov 2021 — An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers. Una vulnerabilidad de control de acceso inapropiado en SCloudBnRReceiver en SecTelephonyProvider versiones anteriores a SMR Nov-2021 Release 1, permite que una aplicación no confiable llame a algunos proveedores protegidos • https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=11 • CWE-284: Improper Access Control •

CVE-2021-25500
https://notcve.org/view.php?id=CVE-2021-25500
05 Nov 2021 — A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise. Una falta de comprobación de entradas en HDCP LDFW versiones anteriores a 1 de SMR Nov-2021, permite a atacantes sobrescribir TZASC, lo que permite comprometer el TEE • https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=11 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •

CVE-2021-0663
https://notcve.org/view.php?id=CVE-2021-0663
25 Oct 2021 — In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844458; Issue ID: ALPS05844458. En audio DSP, se presenta una posible escritura fuera de límites debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/October-2021 • CWE-787: Out-of-bounds Write •

CVE-2021-0662
https://notcve.org/view.php?id=CVE-2021-0662
25 Oct 2021 — In audio DSP, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05844434; Issue ID: ALPS05844434. En audio DSP, se presenta una posible escritura fuera de límites debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/October-2021 • CWE-787: Out-of-bounds Write •