CVE-2023-20920
- EPSS 0.03%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:52
In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...
CVE-2023-20921
- EPSS 0.1%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:52
In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges n...
CVE-2023-20922
- EPSS 0.04%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:52
In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Produ...
CVE-2023-20923
- EPSS 0.01%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:52
In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User intera...
CVE-2023-20924
- EPSS 0.02%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:52
In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege with physical access to the device with no additional execution privileges needed. User interaction is...
CVE-2023-20925
- EPSS 0.04%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:53
In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVE-2023-20928
- EPSS 0.1%
- Veröffentlicht 26.01.2023 21:18:11
- Zuletzt bearbeitet 02.04.2025 15:15:53
In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: And...
CVE-2023-20904
- EPSS 0.04%
- Veröffentlicht 26.01.2023 21:18:10
- Zuletzt bearbeitet 03.04.2025 21:15:37
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVE-2022-20493
- EPSS 0.03%
- Veröffentlicht 26.01.2023 21:15:28
- Zuletzt bearbeitet 03.04.2025 20:15:16
In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exp...
CVE-2022-20494
- EPSS 1.12%
- Veröffentlicht 26.01.2023 21:15:28
- Zuletzt bearbeitet 03.04.2025 21:15:37
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...