- EPSS 0.03%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:13
In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Produ...
CVE-2023-21091
- EPSS 0.02%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:13
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges ne...
CVE-2023-21092
- EPSS 0.01%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 19:15:14
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no additional...
CVE-2023-21093
- EPSS 0.02%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 16:15:34
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges n...
CVE-2023-21094
- EPSS 0.02%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 16:15:34
In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. Us...
CVE-2023-21096
- EPSS 2.53%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 16:15:34
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12...
CVE-2023-21097
- EPSS 0.14%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 16:15:34
In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVE-2023-21098
- EPSS 0.02%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 18:15:27
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed....
CVE-2023-21099
- EPSS 0.03%
- Veröffentlicht 19.04.2023 20:15:11
- Zuletzt bearbeitet 05.02.2025 17:15:12
In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges n...
CVE-2021-0872
- EPSS 0.02%
- Veröffentlicht 19.04.2023 20:15:10
- Zuletzt bearbeitet 05.02.2025 21:15:12
In PVRSRVBridgeRGXKickVRDM of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privile...