Android
by Google
CVEs (8,504)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21274 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21271 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21234 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2023-21230 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information disclosure with no… | ||
| CVE-2023-21268 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21267 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-33912 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33911 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33910 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33909 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33908 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33907 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33906 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-21260 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation. | ||
| CVE-2023-21249 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21243 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed… | ||
| CVE-2023-21240 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21239 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21238 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-20942 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction… |
- risk 0.36cvss 5.5epss 0.00
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.36cvss 5.5epss 0.00
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information disclosure with no…
- risk 0.36cvss 5.5epss 0.00
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.
- risk 0.36cvss 5.5epss 0.00
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed…
- risk 0.36cvss 5.5epss 0.00
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
Page 305 of 426