CVE-2021-0519
published 2021-08-17CVE-2021-0519: In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.1th percentile
In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-176533109
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | external_libavc | >= 10:0 < 10:2021-08-01 | 10:2021-08-01 |
| platform | external_libavc | >= 11:0 < 11:2021-08-01 | 11:2021-08-01 |
| platform | external_libavc | >= 8.1:0 < 8.1:2021-08-01 | 8.1:2021-08-01 |
| platform | external_libavc | >= 9:0 < 9:2021-08-01 | 9:2021-08-01 |
| platform | frameworks_av | >= 10:0 < 10:2021-08-01 | 10:2021-08-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2021-0519: Android Security Bulletin 2021-08-01
CVE: CVE-2021-0519
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-176533109
vendor_android·2021-08-01·CVSS 7.8
CVE-2021-0519 [HIGH] CVE-2021-0519: Android Security Bulletin 2021-08-01
CVE: CVE-2021-0519
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-176533109
Android Security Bulletin 2021-08-01
CVE: CVE-2021-0519
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-176533109
GHSA
GHSA-3x4v-r279-87fr: In BITSTREAM_FLUSH of ih264e_bitstream
ghsa_unreviewed·2022-05-24
CVE-2021-0519 [HIGH] CWE-787 GHSA-3x4v-r279-87fr: In BITSTREAM_FLUSH of ih264e_bitstream
In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-176533109
OSV
CVE-2021-0519: In BITSTREAM_FLUSH of ih264e_bitstream
osv·2021-08-01
CVE-2021-0519 CVE-2021-0519: In BITSTREAM_FLUSH of ih264e_bitstream
In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Qualys
Google Android August 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-08-13·CVSS 7.8
[HIGH] Google Android August 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices | Qualys
The recently released Android Security Bulletin for August 2021 addresses 36 vulnerabilities, out of which 5 are rated as critical vulnerabilities. The vulnerabilities affect open-source components such as the Android Framework, Android Media Framework, and Android System. The vulnerabilities also affect Kernel components, Widevine DRM, MediaTek, QUALCOMM components, and QUALCOMM closed-source components.
#### Media Framework Escalation of Privilege (EoP) and Information Disclosure (ID) Vulnerability
Google released a patch to fix a critical vulnerability (CVE-2021-0519). This vulnerability has a CVSSv3 base score of 8.4 and successful exploitation could enable a local malicious application to bypass operating system protections that isolate application data from other applications. It s
Qualys
Google Android August 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices
blogs_qualys·2021-08-13·CVSS 7.8
[HIGH] Google Android August 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices
The recently released Android Security Bulletin for August 2021 addresses 36 vulnerabilities, out of which 5 are rated as critical vulnerabilities. The vulnerabilities affect open-source components such as the Android Framework, Android Media Framework, and Android System. The vulnerabilities also affect Kernel components, Widevine DRM, MediaTek, QUALCOMM components, and QUALCOMM closed-source components.
## Media Framework Escalation of Privilege (EoP) and Information Disclosure (ID) Vulnerability
Google released a patch to fix a critical vulnerability (CVE-2021-0519). This vulnerability has a CVSSv3 base score of 8.4 and successful exploitation could enable a local malicious application to bypass operating system protections that isolate application data from other applications. It sho
2021-08-17
Published