|
1001
|
9.8
-
|
CRITICAL
Network
|
In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no a…
|
NVD-CWE-noinfo
|
CVE-2021-0945
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2024-11-21 14:43
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1002
|
7.5
-
|
HIGH
Network
|
In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional e…
|
NVD-CWE-noinfo
|
CVE-2023-21144
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1003
|
5.5
-
|
MEDIUM
Local
|
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution …
|
CWE-20
Improper Input Validation
|
CVE-2023-21143
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1004
|
5.5
-
|
MEDIUM
Local
|
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed…
|
NVD-CWE-noinfo
|
CVE-2023-21142
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1005
|
5.5
-
|
MEDIUM
Local
|
In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional executio…
|
NVD-CWE-noinfo
|
CVE-2023-21141
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1006
|
7.8
-
|
HIGH
Local
|
In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution pri…
|
NVD-CWE-noinfo
|
CVE-2023-21139
|
cpe:2.3:o:google:android:13.0:*
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1007
|
5.5
-
|
MEDIUM
Local
|
In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not ne…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2023-21137
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1008
|
5.5
-
|
MEDIUM
Local
|
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution p…
|
CWE-20
Improper Input Validation
|
CVE-2023-21136
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1009
|
7.8
-
|
HIGH
Local
|
In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitigations due to a logic error in the code. This could lead to local escalation of…
|
NVD-CWE-noinfo
|
CVE-2023-21131
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1010
|
9.8
-
|
CRITICAL
Network
|
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileg…
|
CWE-125
Out-of-bounds Read
|
CVE-2023-21130
|
cpe:2.3:o:google:android:13.0:*
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|