CVE-2023-21393
- EPSS 0.1%
- Veröffentlicht 30.10.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:42:46
In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21394
- EPSS 0.1%
- Veröffentlicht 30.10.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:42:46
In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User int...
CVE-2023-21395
- EPSS 0.18%
- Veröffentlicht 30.10.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:42:46
In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21396
- EPSS 0.11%
- Veröffentlicht 30.10.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:42:46
In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21397
- EPSS 0.1%
- Veröffentlicht 30.10.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:42:46
In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21398
- EPSS 0.12%
- Veröffentlicht 30.10.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:42:46
In sdksandbox, there is a possible strandhogg style overlay attack due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21372
- EPSS 0.09%
- Veröffentlicht 30.10.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:42:44
In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-21373
- EPSS 0.08%
- Veröffentlicht 30.10.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:42:44
In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ...
CVE-2023-21367
- EPSS 0.09%
- Veröffentlicht 30.10.2023 17:15:52
- Zuletzt bearbeitet 21.11.2024 07:42:43
In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...
CVE-2023-21368
- EPSS 0.09%
- Veröffentlicht 30.10.2023 17:15:52
- Zuletzt bearbeitet 21.11.2024 07:42:43
In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.