Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40075 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is… | ||
| CVE-2023-40074 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-40073 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-35668 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-42749 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42744 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42742 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42741 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42737 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42734 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42733 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42732 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42730 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42728 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42723 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42721 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In flv extractor, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42720 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In video service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42719 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In video service, there is a possible out of bounds read due to a incorrect bounds check. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-42718 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42715 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
- risk 0.36cvss 5.5epss 0.00
In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is…
- risk 0.36cvss 5.5epss 0.00
In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In phasecheckserver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In camera service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In flv extractor, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video service, there is a possible out of bounds read due to a incorrect bounds check. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Page 295 of 426