CVE-2023-21231
- EPSS 0.01%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:25
In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected activity due to a missing permission check. This could lead to local escalation of privilege with no ...
CVE-2023-21232
- EPSS 0%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:25
In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVE-2023-21233
- EPSS 0.14%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:26
In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21234
- EPSS 0.01%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:26
In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional exec...
CVE-2023-21235
- EPSS 0%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:27
In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed....
CVE-2023-21271
- EPSS 0.02%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:31
In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVE-2023-21272
- EPSS 0.01%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:32
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. ...
CVE-2023-21273
- EPSS 0.03%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:32
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed fo...
CVE-2023-21274
- EPSS 0.02%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:32
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVE-2023-21275
- EPSS 0%
- Veröffentlicht 14.08.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:42:32
In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution ...