CVE-2023-40073
- EPSS 0.05%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:43
In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-40074
- EPSS 0.09%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:43
In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-40075
- EPSS 0.07%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:43
In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privilege...
CVE-2023-40076
- EPSS 0.01%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 29.05.2025 14:15:31
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVE-2023-40077
- EPSS 9.96%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:43
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-40078
- EPSS 0.11%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:43
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. ...
CVE-2023-40079
- EPSS 0.01%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:43
In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...
CVE-2023-40080
- EPSS 0.04%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:43
In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...
CVE-2023-40081
- EPSS 0.03%
- Veröffentlicht 04.12.2023 23:15:23
- Zuletzt bearbeitet 21.11.2024 08:18:44
In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interactio...
CVE-2023-21162
- EPSS 0.11%
- Veröffentlicht 04.12.2023 23:15:22
- Zuletzt bearbeitet 21.11.2024 07:42:18
In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed ...