cve entity

CVE-2021-25370

3 source-linked records in the current knowledge graph.

high

CVE-2021-25337: Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25369: Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25370: Samsung Mobile Devices Memory Corruption Vulnerability

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution