CVE-2021-0687
published 2021-10-06CVE-2021-0687: In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution…
PriorityP418medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.11%
1.7th percentile
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-188913943
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2021-09-01 | 10:2021-09-01 |
| platform | frameworks_base | >= 11:0 < 11:2021-09-01 | 11:2021-09-01 |
| platform | frameworks_base | >= 8.1:0 < 8.1:2021-09-01 | 8.1:2021-09-01 |
| platform | frameworks_base | >= 9:0 < 9:2021-09-01 | 9:2021-09-01 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2021-0687: Android Security Bulletin 2021-09-01
CVE: CVE-2021-0687
Severity: CRITICAL
Type: DoS
Affected AOSP versions: 8
vendor_android·2021-09-01·CVSS 5.0
CVE-2021-0687 [MEDIUM] CVE-2021-0687: Android Security Bulletin 2021-09-01
CVE: CVE-2021-0687
Severity: CRITICAL
Type: DoS
Affected AOSP versions: 8
Android Security Bulletin 2021-09-01
CVE: CVE-2021-0687
Severity: CRITICAL
Type: DoS
Affected AOSP versions: 8.1, 9, 10, 11
References: A-188913943
GHSA
GHSA-f4mh-2678-3x2m: In ellipsize of Layout
ghsa_unreviewed·2022-05-24
CVE-2021-0687 [MEDIUM] CWE-20 GHSA-f4mh-2678-3x2m: In ellipsize of Layout
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-188913943
OSV
CVE-2021-0687: In ellipsize of Layout
osv·2021-09-01
CVE-2021-0687 CVE-2021-0687: In ellipsize of Layout
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
Qualys
Google Android September 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices
blogs_qualys·2021-09-20·CVSS 5.0
[MEDIUM] Google Android September 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices
The recently released Android Security Bulletin for September 2021 addresses 40 vulnerabilities, out of which 7 are rated as critical vulnerabilities. The vulnerabilities affect open-source components such as the Android Framework, Android Media Framework, and Android System. The vulnerabilities also affect Kernel components, MediaTek, Unisoc components, QUALCOMM components, and QUALCOMM closed-source components.
## QUALCOMM Closed-source Components Improper Validation of Array Index Vulnerability
Google released a patch to fix an improper validation of array index critical vulnerability (CVE-2021-1933). This vulnerability has a CVSSv3.1 base score of 9.8, and successful exploitation of the vulnerability allows a remote attacker to trigger memory corruption and execute arbitrary code on
Qualys
Google Android September 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-09-20·CVSS 5.0
[MEDIUM] Google Android September 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices | Qualys
The recently released Android Security Bulletin for September 2021 addresses 40 vulnerabilities, out of which 7 are rated as critical vulnerabilities. The vulnerabilities affect open-source components such as the Android Framework, Android Media Framework, and Android System. The vulnerabilities also affect Kernel components, MediaTek, Unisoc components, QUALCOMM components, and QUALCOMM closed-source components.
### QUALCOMM Closed-source Components Improper Validation of Array Index Vulnerability
Google released a patch to fix an improper validation of array index critical vulnerability (CVE-2021-1933). This vulnerability has a CVSSv3.1 base score of 9.8, and successful exploitation of the vulnerability allows a remote attacker to trigger memory corruption and execute arbitrary code on
2021-10-06
Published