CVE-2021-0400
published 2021-04-13CVE-2021-0400: In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.13%
2.9th percentile
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation. This could lead to incorrect reporting of location data to emergency services with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-177561690
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2021-04-01 | 10:2021-04-01 |
| platform | frameworks_base | >= 11:0 < 11:2021-04-01 | 11:2021-04-01 |
| platform | frameworks_base | >= 9:0 < 9:2021-04-01 | 9:2021-04-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g763-mxvp-v63f: In injectBestLocation and handleUpdateLocation of GnssLocationProvider
ghsa_unreviewed·2022-05-24
CVE-2021-0400 [MEDIUM] CWE-20 GHSA-g763-mxvp-v63f: In injectBestLocation and handleUpdateLocation of GnssLocationProvider
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation. This could lead to incorrect reporting of location data to emergency services with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-177561690
Kernel
drm/amdgpu: Fix even more out of bound writes from debugfs
kernel_security·2021-10-27·CVSS 6.7
CVE-2021-42327 [MEDIUM] drm/amdgpu: Fix even more out of bound writes from debugfs
drm/amdgpu: Fix even more out of bound writes from debugfs
CVE-2021-42327 was fixed by:
commit f23750b5b3d98653b31d4469592935ef6364ad67
Author: Thelford Williams
Date: Wed Oct 13 16:04:13 2021 -0400
drm/amdgpu: fix out of bounds write
but amdgpu_dm_debugfs.c contains more of the same issue so fix the
remaining ones.
v2:
* Add missing fix in dp_max_bpc_write (Harry Wentland)
Fixes: 918698d5c2b5 ("drm/amd/display: Return the number of bytes parsed than allocated")
Signed-off-by: Patrik Jakobsson
Reviewed-by: Harry Wentland
Signed-off-by: Alex Deucher
Cc: [email protected]
Kernel
drm/amdgpu: Fix even more out of bound writes from debugfs
kernel_security·2021-10-27·CVSS 6.7
CVE-2021-42327 [MEDIUM] drm/amdgpu: Fix even more out of bound writes from debugfs
drm/amdgpu: Fix even more out of bound writes from debugfs
CVE-2021-42327 was fixed by:
commit f23750b5b3d98653b31d4469592935ef6364ad67
Author: Thelford Williams
Date: Wed Oct 13 16:04:13 2021 -0400
drm/amdgpu: fix out of bounds write
but amdgpu_dm_debugfs.c contains more of the same issue so fix the
remaining ones.
v2:
* Add missing fix in dp_max_bpc_write (Harry Wentland)
Fixes: 918698d5c2b5 ("drm/amd/display: Return the number of bytes parsed than allocated")
Signed-off-by: Patrik Jakobsson
Reviewed-by: Harry Wentland
Signed-off-by: Alex Deucher
OSV
CVE-2021-0400: In injectBestLocation and handleUpdateLocation of GnssLocationProvider
osv·2021-04-01
CVE-2021-0400 CVE-2021-0400: In injectBestLocation and handleUpdateLocation of GnssLocationProvider
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation. This could lead to incorrect reporting of location data to emergency services with User execution privileges needed. User interaction is not needed for exploitation.
Red Hat
kernel: drm/amdgpu: Fix even more out of bound writes from debugfs
vendor_redhat·2024-05-22·CVSS 6.7
CVE-2021-47489 [MEDIUM] CWE-787 kernel: drm/amdgpu: Fix even more out of bound writes from debugfs
kernel: drm/amdgpu: Fix even more out of bound writes from debugfs
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix even more out of bound writes from debugfs
CVE-2021-42327 was fixed by:
commit f23750b5b3d98653b31d4469592935ef6364ad67
Author: Thelford Williams
Date: Wed Oct 13 16:04:13 2021 -0400
drm/amdgpu: fix out of bounds write
but amdgpu_dm_debugfs.c contains more of the same issue so fix the
remaining ones.
v2:
* Add missing fix in dp_max_bpc_write (Harry Wentland)
A vulnerability has been identified in the Linux kernel's amdgpu_dm_debugfs.c file, part of the AMD GPU display manager debug filesystem. This flaw involves improper out-of-bounds write behaviors within a series of functions. Exploitation of these vulnerabilities could lead to memory c
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2021-0400: Android Security Bulletin 2021-04-01
CVE: CVE-2021-0400
Severity: HIGH
Type: EoP
Affected AOSP versions: 9, 10, 11
References: A-177561690
vendor_android·2021-04-01·CVSS 5.5
CVE-2021-0400 [MEDIUM] CVE-2021-0400: Android Security Bulletin 2021-04-01
CVE: CVE-2021-0400
Severity: HIGH
Type: EoP
Affected AOSP versions: 9, 10, 11
References: A-177561690
Android Security Bulletin 2021-04-01
CVE: CVE-2021-0400
Severity: HIGH
Type: EoP
Affected AOSP versions: 9, 10, 11
References: A-177561690
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-13
Published