CVE-2023-21086
- EPSS 0%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 20:15:35
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with ...
CVE-2023-21087
- EPSS 0.03%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:12
In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.P...
CVE-2023-21088
- EPSS 0%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:13
In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privi...
CVE-2023-21089
- EPSS 0.02%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:13
In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foreground service alive while the app is in the background. This could lead to local escalation of privilege with no additional execution privileges needed. ...
- EPSS 0.03%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:13
In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Produ...
CVE-2023-21091
- EPSS 0.02%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:13
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges ne...
CVE-2023-21092
- EPSS 0.01%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:14
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no additional...
CVE-2023-21093
- EPSS 0.03%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 16:15:34
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges n...
CVE-2023-21094
- EPSS 0.01%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 16:15:34
In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVE-2023-21096
- EPSS 1.91%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 16:15:34
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12...