Vendor CVEs
All CVEs
16,116 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30913 | Med | 0.36 | 5.5 | 0.00 | Jul 12, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-21211 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android… | ||
| CVE-2023-21205 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21200 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21198 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21177 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is… | ||
| CVE-2023-21173 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21168 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In convertCbYCrY of ColorConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21167 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21160 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In BuildSetTcsFci of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21155 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In BuildSetRadioNode of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21152 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In FaceStatsAnalyzer::InterpolateWeightList of face_stats_analyzer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21143 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21142 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21141 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21137 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12… | ||
| CVE-2023-21136 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21105 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-30915 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-30914 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-30866 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-30865 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2022-48448 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48447 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48446 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48445 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48444 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48443 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48442 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48441 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48440 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48391 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2023-21118 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21112 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-21111 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21104 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID:… | ||
| CVE-2023-21103 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2023-20930 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-20914 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User… | ||
| CVE-2023-20706 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860. | ||
| CVE-2023-20705 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870. | ||
| CVE-2023-20704 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826. | ||
| CVE-2023-20703 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767853; Issue ID: ALPS07767853. | ||
| CVE-2022-48379 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48378 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48377 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48376 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48375 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48371 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges. | ||
| CVE-2022-48370 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges. |
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android…
- risk 0.36cvss 5.5epss 0.00
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…
- risk 0.36cvss 5.5epss 0.00
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In convertCbYCrY of ColorConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In setProfileName of DevicePolicyManagerService.java, there is a possible way to crash the SystemUI menu due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In BuildSetTcsFci of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In BuildSetRadioNode of protocolmiscbuilder.cpp, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In FaceStatsAnalyzer::InterpolateWeightList of face_stats_analyzer.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12…
- risk 0.36cvss 5.5epss 0.00
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID:…
- risk 0.36cvss 5.5epss 0.00
In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User…
- risk 0.36cvss 5.5epss 0.00
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.
- risk 0.36cvss 5.5epss 0.00
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.
- risk 0.36cvss 5.5epss 0.00
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.
- risk 0.36cvss 5.5epss 0.00
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767853; Issue ID: ALPS07767853.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
Page 214 of 323