|
541
|
8.8
-
|
HIGH
Adjacent
|
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution…
|
CWE-787
Out-of-bounds Write
|
CVE-2023-40129
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
542
|
7.8
-
|
HIGH
Local
|
In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges ne…
|
CWE-787
Out-of-bounds Write
|
CVE-2023-40128
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
543
|
3.3
-
|
LOW
Local
|
In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User int…
|
NVD-CWE-Other
|
CVE-2023-40127
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
544
|
7.8
-
|
HIGH
Local
|
In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution pri…
|
NVD-CWE-noinfo
|
CVE-2023-40125
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
545
|
5.5
-
|
MEDIUM
Local
|
In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional exe…
|
NVD-CWE-Other
|
CVE-2023-40123
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
546
|
5.5
-
|
MEDIUM
Local
|
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2023-40121
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
547
|
7.8
-
|
HIGH
Local
|
In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional…
|
NVD-CWE-noinfo
|
CVE-2023-40120
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
548
|
7.8
-
|
HIGH
Local
|
In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privileg…
|
NVD-CWE-noinfo
|
CVE-2023-40116
|
cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:google:android:11.0:*
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
549
|
7.5
-
|
HIGH
Network
|
In Init of protocolnetadapter.cpp, there is a possible out of bounds read
due to a missing bounds check. This could lead to remote information
disclosure with no additional execution privil…
|
CWE-125
Out-of-bounds Read
|
CVE-2023-35663
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2024-11-21 17:08
2023-10-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
550
|
7.5
-
|
HIGH
Network
|
In multiple functions of protocolembmsadapter.cpp, there is a possible out
of bounds read due to a missing bounds check. This could lead to remote
information disclosure with no additional e…
|
CWE-125
Out-of-bounds Read
|
CVE-2023-35656
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2024-11-21 17:08
2023-10-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|