|
821
|
7.3
-
|
HIGH
Local
|
In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User exec…
|
CWE-20
Improper Input Validation
|
CVE-2023-21251
|
cpe:2.3:o:google:android:13.1:* cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
822
|
9.8
-
|
CRITICAL
Network
|
In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.…
|
CWE-787
Out-of-bounds Write
|
CVE-2023-21250
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
823
|
5.5
-
|
MEDIUM
Local
|
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User e…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2023-21249
|
cpe:2.3:o:google:android:13.0:*
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
824
|
7.8
-
|
HIGH
Local
|
In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local …
|
CWE-862
Missing Authorization
|
CVE-2023-21248
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
825
|
7.8
-
|
HIGH
Local
|
In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to l…
|
CWE-862
Missing Authorization
|
CVE-2023-21247
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:*
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
826
|
3.3
-
|
LOW
Local
|
In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2023-21246
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
827
|
7.8
-
|
HIGH
Local
|
In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead …
|
NVD-CWE-noinfo
|
CVE-2023-21245
|
cpe:2.3:o:google:android:13.1:* cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
828
|
5.5
-
|
MEDIUM
Local
|
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of se…
|
CWE-120
Classic Buffer Overflow
|
CVE-2023-21243
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
829
|
7.8
-
|
HIGH
Local
|
In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges need…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2023-21241
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
830
|
5.5
-
|
MEDIUM
Local
|
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2023-21240
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 16:42
2023-07-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|