|
531
|
7.8
-
|
HIGH
Local
|
In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no…
|
CWE-416
Use After Free
|
CVE-2023-40140
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
5.5
-
|
MEDIUM
Local
|
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges neede…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2023-40139
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
3.3
-
|
LOW
Local
|
In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional executio…
|
NVD-CWE-Other
|
CVE-2023-40137
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
3.3
-
|
LOW
Local
|
In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privile…
|
NVD-CWE-Other
|
CVE-2023-40136
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
3.3
-
|
LOW
Local
|
In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution …
|
NVD-CWE-Other
|
CVE-2023-40135
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
3.3
-
|
LOW
Local
|
In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges…
|
NVD-CWE-Other
|
CVE-2023-40134
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
5.5
-
|
MEDIUM
Local
|
In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional executio…
|
NVD-CWE-Other
|
CVE-2023-40133
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
7.0
-
|
HIGH
Local
|
In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User inte…
|
CWE-416
Use After Free
|
CVE-2023-40131
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
7.8
-
|
HIGH
Local
|
In onBindingDied of CallRedirectionProcessor.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity lau…
|
NVD-CWE-noinfo
|
CVE-2023-40130
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
8.8
-
|
HIGH
Adjacent
|
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution…
|
CWE-787
Out-of-bounds Write
|
CVE-2023-40129
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|