|
1011
|
7.8
-
|
HIGH
Local
|
In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background due to a BAL bypass. This could lead to local esc…
|
NVD-CWE-noinfo
|
CVE-2023-21129
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1012
|
7.8
-
|
HIGH
Local
|
In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This could lead to local escalation of privilege with no …
|
NVD-CWE-noinfo
|
CVE-2023-21128
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1013
|
8.8
-
|
HIGH
Network
|
In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2023-21127
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1014
|
7.8
-
|
HIGH
Local
|
In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. This could lead to local escalation of privilege wit…
|
NVD-CWE-noinfo
|
CVE-2023-21126
|
cpe:2.3:o:google:android:13.0:*
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1015
|
7.8
-
|
HIGH
Local
|
In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. U…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2023-21124
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1016
|
7.8
-
|
HIGH
Local
|
In multiple functions of multiple files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalati…
|
CWE-862
Missing Authorization
|
CVE-2023-21123
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1017
|
7.8
-
|
HIGH
Local
|
In various functions of various files, there is a possible way to bypass the DISALLOW_DEBUGGING_FEATURES restriction for tracing due to a missing permission check. This could lead to local escalation…
|
CWE-862
Missing Authorization
|
CVE-2023-21122
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1018
|
7.8
-
|
HIGH
Local
|
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of…
|
CWE-20
Improper Input Validation
|
CVE-2023-21121
|
cpe:2.3:o:google:android:12.0:- cpe:2.3:o:google:android:11.0:-
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1019
|
7.8
-
|
HIGH
Local
|
In multiple functions of cdm_engine.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. U…
|
CWE-416 CWE-667
Use After Free Improper Locking
|
CVE-2023-21120
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1020
|
8.8
-
|
HIGH
Adjacent
|
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additio…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2023-21115
|
cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:google:android:11.0:*
|
|
|
|
|
2024-11-21 16:42
2023-06-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|