CVE-2021-0322
published 2021-01-11CVE-2021-0322: In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local…
PriorityP421medium5CVSS 3.1
AVLACLPRLUIRSUCHINAN
EPSS
0.16%
5.7th percentile
In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: Android; Versions: Android-10, Android-11, Android-9; Android ID: A-159145361.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2021-01-01 | 10:2021-01-01 |
| platform | frameworks_base | >= 11:0 < 11:2021-01-01 | 11:2021-01-01 |
| platform | frameworks_base | >= 9:0 < 9:2021-01-01 | 9:2021-01-01 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h5w7-wjh6-r5wj: In onCreate of SlicePermissionActivity
ghsa_unreviewed·2022-05-24
CVE-2021-0322 [MEDIUM] CWE-20 GHSA-h5w7-wjh6-r5wj: In onCreate of SlicePermissionActivity
In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: Android; Versions: Android-10, Android-11, Android-9; Android ID: A-159145361.
OSV
CVE-2021-0322: In onCreate of SlicePermissionActivity
osv·2021-01-01
CVE-2021-0322 CVE-2021-0322: In onCreate of SlicePermissionActivity
In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
Red Hat
kernel: sctp: local DoS: unprivileged user can cause BUG()
vendor_redhat·2022-02-03·CVSS 5.5
CVE-2021-3894 [MEDIUM] CWE-400 kernel: sctp: local DoS: unprivileged user can cause BUG()
kernel: sctp: local DoS: unprivileged user can cause BUG()
A vulnerability was found in the Linux kernel. This flaw allows an unprivileged local user to panic the system, resulting in a denial of service by calling setsockopt(2) with specially crafted arguments. The highest threat from this vulnerability is to system availability.
Statement: This flaw was found to be a duplicate of CVE-2022-0322. Please see https://access.redhat.com/security/cve/CVE-2022-0322 for information about affected products and security errata.
Mitigation: As the SCTP module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions:
# echo "install sctp /bin/true" >> /etc/modprobe.d/disable-sctp.conf
The system will need to be restarted if th
Android
CVE-2021-0322: Android Security Bulletin 2021-01-01
CVE: CVE-2021-0322
Severity: HIGH
Type: ID
Affected AOSP versions: 9, 10, 11
References: A-159145361
[2]
vendor_android·2021-01-01·CVSS 5.0
CVE-2021-0322 [MEDIUM] CVE-2021-0322: Android Security Bulletin 2021-01-01
CVE: CVE-2021-0322
Severity: HIGH
Type: ID
Affected AOSP versions: 9, 10, 11
References: A-159145361
[2]
Android Security Bulletin 2021-01-01
CVE: CVE-2021-0322
Severity: HIGH
Type: ID
Affected AOSP versions: 9, 10, 11
References: A-159145361
[2]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-11
Published