|
761
|
5.5
-
|
MEDIUM
Local
|
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosu…
|
NVD-CWE-noinfo
|
CVE-2023-21267
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:- cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
762
|
7.5
-
|
HIGH
Network
|
In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n…
|
CWE-295
Improper Certificate Validation
|
CVE-2023-21265
|
cpe:2.3:o:google:android:13.1:- cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.0:- cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
763
|
6.7
-
|
MEDIUM
Local
|
In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with Syst…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2023-21264
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
764
|
9.8
-
|
CRITICAL
Network
|
In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege wi…
|
NVD-CWE-noinfo
|
CVE-2023-21242
|
cpe:2.3:o:google:android:13.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
765
|
6.8
-
|
MEDIUM
Physics
|
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with phy…
|
CWE-862
Missing Authorization
|
CVE-2023-21140
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
766
|
6.8
-
|
MEDIUM
Physics
|
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with phy…
|
CWE-862
Missing Authorization
|
CVE-2023-21134
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
767
|
6.8
-
|
MEDIUM
Physics
|
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with phy…
|
CWE-862
Missing Authorization
|
CVE-2023-21133
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
768
|
6.8
-
|
MEDIUM
Physics
|
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with phy…
|
CWE-862
Missing Authorization
|
CVE-2023-21132
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
769
|
9.8
-
|
CRITICAL
Network
|
In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no ad…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2023-20965
|
cpe:2.3:o:google:android:13.0:-
|
|
|
|
|
2024-11-21 16:41
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
770
|
4.4
-
|
MEDIUM
Local
|
In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is …
|
CWE-125
Out-of-bounds Read
|
CVE-2023-20813
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 16:41
2023-08-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|