|
1191
|
7.8
-
|
HIGH
Local
|
In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privilege…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2023-21097
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1192
|
7.8
-
|
HIGH
Local
|
In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege…
|
CWE-862
Missing Authorization
|
CVE-2023-21094
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1193
|
7.8
-
|
HIGH
Local
|
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error. This could lead to local escalation of …
|
CWE-22
Path Traversal
|
CVE-2023-21093
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1194
|
5.5
-
|
MEDIUM
Local
|
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user bo…
|
CWE-862
Missing Authorization
|
CVE-2023-21091
|
cpe:2.3:o:google:android:13.0:*
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1195
|
5.0
-
|
MEDIUM
Local
|
In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2023-21090
|
cpe:2.3:o:google:android:13.0:*
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1196
|
7.8
-
|
HIGH
Local
|
In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foreground service alive while the app is in the background. This could lead to local escalation of privile…
|
NVD-CWE-noinfo
|
CVE-2023-21089
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1197
|
7.8
-
|
HIGH
Local
|
In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalat…
|
NVD-CWE-noinfo
|
CVE-2023-21088
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1198
|
5.5
-
|
MEDIUM
Local
|
In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed…
|
NVD-CWE-Other
|
CVE-2023-21087
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1199
|
7.8
-
|
HIGH
Local
|
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local e…
|
NVD-CWE-noinfo
|
CVE-2023-21086
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1200
|
8.8
-
|
HIGH
Adjacent
|
In nci_snd_set_routing_cmd of nci_hmsgs.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional exec…
|
CWE-787
Out-of-bounds Write
|
CVE-2023-21085
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-04-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|