|
831
|
7.8
-
|
HIGH
Local
|
In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to l…
|
CWE-862
Missing Authorization
|
CVE-2023-21247
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
832
|
3.3
-
|
LOW
Local
|
In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2023-21246
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
833
|
7.8
-
|
HIGH
Local
|
In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead …
|
NVD-CWE-noinfo
|
CVE-2023-21245
|
cpe:2.3:o:google:android:13.1:* cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
834
|
5.5
-
|
MEDIUM
Local
|
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of se…
|
CWE-120
Classic Buffer Overflow
|
CVE-2023-21243
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
835
|
7.8
-
|
HIGH
Local
|
In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges need…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2023-21241
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
836
|
5.5
-
|
MEDIUM
Local
|
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2023-21240
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
837
|
5.5
-
|
MEDIUM
Local
|
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execu…
|
NVD-CWE-Other
|
CVE-2023-21239
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
838
|
5.5
-
|
MEDIUM
Local
|
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges ne…
|
NVD-CWE-Other
|
CVE-2023-21238
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
839
|
7.8
-
|
HIGH
Local
|
In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege w…
|
NVD-CWE-noinfo
|
CVE-2023-21145
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
840
|
5.5
-
|
MEDIUM
Local
|
In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalatio…
|
NVD-CWE-noinfo
|
CVE-2023-20942
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 16:41
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|