|
751
|
5.5
-
|
MEDIUM
Local
|
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition …
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2023-21230
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:11.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
752
|
7.8
-
|
HIGH
Local
|
In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent. This could lead to local escalation of privileg…
|
NVD-CWE-noinfo
|
CVE-2023-21229
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:11.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
753
|
5.5
-
|
MEDIUM
Local
|
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional …
|
CWE-22
Path Traversal
|
CVE-2023-21268
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:- cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
754
|
7.8
-
|
HIGH
Local
|
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with…
|
CWE-269
Improper Privilege Management
|
CVE-2023-21269
|
cpe:2.3:o:google:android:13.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
755
|
5.5
-
|
MEDIUM
Local
|
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosu…
|
NVD-CWE-noinfo
|
CVE-2023-21267
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:- cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
756
|
7.5
-
|
HIGH
Network
|
In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n…
|
CWE-295
Improper Certificate Validation
|
CVE-2023-21265
|
cpe:2.3:o:google:android:13.1:- cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.0:- cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
757
|
6.7
-
|
MEDIUM
Local
|
In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with Syst…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2023-21264
|
cpe:2.3:o:google:android:-:*
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
758
|
9.8
-
|
CRITICAL
Network
|
In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege wi…
|
NVD-CWE-noinfo
|
CVE-2023-21242
|
cpe:2.3:o:google:android:13.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
759
|
6.8
-
|
MEDIUM
Physics
|
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with phy…
|
CWE-862
Missing Authorization
|
CVE-2023-21140
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
760
|
6.8
-
|
MEDIUM
Physics
|
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with phy…
|
CWE-862
Missing Authorization
|
CVE-2023-21134
|
cpe:2.3:o:google:android:13.0:- cpe:2.3:o:google:android:12.1:- cpe:2.3:o:google:android:12.0:-
|
|
|
|
|
2024-11-21 16:42
2023-08-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|