|
591
|
5.5
-
|
MEDIUM
Local
|
In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User …
|
CWE-862
Missing Authorization
|
CVE-2023-21294
|
cpe:2.3:o:google:android:*:*
|
|
|
|
14.0
|
2024-11-21 16:42
2023-10-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
592
|
5.5
-
|
MEDIUM
Local
|
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation o…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2023-21293
|
cpe:2.3:o:google:android:*:*
|
|
|
|
14.0
|
2024-11-21 16:42
2023-10-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
593
|
5.5
-
|
MEDIUM
Local
|
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information di…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2022-20264
|
cpe:2.3:o:google:android:*:*
|
|
|
|
14.0
|
2024-11-21 15:42
2023-10-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
594
|
7.8
-
|
HIGH
Local
|
In NFC, there is a possible way to setup a default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional …
|
CWE-862
Missing Authorization
|
CVE-2021-39810
|
cpe:2.3:o:google:android:14.0:* cpe:2.3:o:google:android:*:*
|
|
|
|
14.0
|
2024-11-21 15:20
2023-10-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
595
|
3.3
-
|
LOW
Local
|
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges neede…
|
NVD-CWE-Other
|
CVE-2023-40138
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
596
|
7.8
-
|
HIGH
Local
|
In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privi…
|
NVD-CWE-noinfo
|
CVE-2023-40117
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
597
|
7.8
-
|
HIGH
Local
|
In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no…
|
CWE-416
Use After Free
|
CVE-2023-40140
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
598
|
5.5
-
|
MEDIUM
Local
|
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges neede…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2023-40139
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
599
|
3.3
-
|
LOW
Local
|
In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional executio…
|
NVD-CWE-Other
|
CVE-2023-40137
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
600
|
3.3
-
|
LOW
Local
|
In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privile…
|
NVD-CWE-Other
|
CVE-2023-40136
|
cpe:2.3:o:google:android:13.0:* cpe:2.3:o:google:android:12.1:* cpe:2.3:o:google:android:12.0:* cpe:2.3:o:goog…
|
|
|
|
|
2024-11-21 17:18
2023-10-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|