CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2023-45775

    Last Modified: 21 Nov 2024

    In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-45774

    Last Modified: 2 Dec 2024

    In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's image due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-45773

    Last Modified: 21 Nov 2024

    In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40103

    Last Modified: 21 Nov 2024

    In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40098

    Last Modified: 21 Nov 2024

    In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40097

    Last Modified: 21 Nov 2024

    In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40096

    Last Modified: 21 Nov 2024

    In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the background due to a missing flag. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40095

    Last Modified: 2 Dec 2024

    In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due to a missing check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40094

    Last Modified: 21 Nov 2024

    In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40092

    Last Modified: 21 Nov 2024

    In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40091

    Last Modified: 21 Nov 2024

    In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-40090

    Last Modified: 21 Nov 2024

    In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40089

    Last Modified: 21 Nov 2024

    In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-40088

    Last Modified: 21 Nov 2024

    In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    8.8
    High

    CVE-2023-40087

    Last Modified: 21 Nov 2024

    In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40084

    Last Modified: 21 Nov 2024

    In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40083

    Last Modified: 21 Nov 2024

    In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-40082

    Last Modified: 2 Dec 2024

    In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40081

    Last Modified: 21 Nov 2024

    In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40080

    Last Modified: 21 Nov 2024

    In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.8
    High

    CVE-2023-40079

    Last Modified: 21 Nov 2024

    In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-40078

    Last Modified: 21 Nov 2024

    In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    8.1
    High

    CVE-2023-40077

    Last Modified: 21 Nov 2024

    In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40076

    Last Modified: 29 May 2025

    In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40075

    Last Modified: 21 Nov 2024

    In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40074

    Last Modified: 21 Nov 2024

    In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-40073

    Last Modified: 21 Nov 2024

    In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-35690

    Last Modified: 2 Dec 2024

    In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    5.5
    Medium

    CVE-2023-35668

    Last Modified: 21 Nov 2024

    In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21403

    Last Modified: 21 Nov 2024

    In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21402

    Last Modified: 21 Nov 2024

    In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21401

    Last Modified: 2 Dec 2024

    In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21263

    Last Modified: 21 Nov 2024

    In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21228

    Last Modified: 21 Nov 2024

    In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-21227

    Last Modified: 21 Nov 2024

    In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclosure. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21218

    Last Modified: 21 Nov 2024

    In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21217

    Last Modified: 21 Nov 2024

    In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21216

    Last Modified: 29 May 2025

    In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21215

    Last Modified: 21 Nov 2024

    In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21166

    Last Modified: 21 Nov 2024

    In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21164

    Last Modified: 21 Nov 2024

    In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21163

    Last Modified: 21 Nov 2024

    In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    9.8
    Critical

    CVE-2023-21162

    Last Modified: 2 Dec 2024

    In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2023
    7.7
    High

    CVE-2023-49280

    Last Modified: 27 Nov 2024

    XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to edit any page by default, and the changes are then exported in an XML file that anyone can download. So it's possible for an attacker to obtain password hash of users by performing an edit on the user profiles and then downloading the XML file that has been created. This is also true for any document that might contain password field and that a user can view. This vulnerability impacts all version of Change Request, but the impact depends on the rights that has been set on the wiki since it requires for the user to have the Change request right (allowed by default) and view rights on the page to target. This issue cannot be easily exploited in an automated way. The patch consists in denying to users the right of editing pages that contains a password field with change request. It means that already existing change request for those pages won't be removed by the patch, administrators needs to take care of it. The patch is provided in Change Request 1.10, administrators should upgrade immediately. It's possible to workaround the vulnerability by denying manually the Change request right on some spaces, such as XWiki space which will include any user profile by default.

    Published: 4 Dec 2023
    4.8
    Medium

    CVE-2023-5809

    Last Modified: 21 Nov 2024

    The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 4 Dec 2023
    6.1
    Medium

    CVE-2023-5141

    Last Modified: 21 Nov 2024

    The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 4 Dec 2023
    7.5
    High

    CVE-2023-6063

    Last Modified: 21 Nov 2024

    The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-5884

    Last Modified: 21 Nov 2024

    The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

    Published: 4 Dec 2023
    7.2
    High

    CVE-2023-5108

    Last Modified: 21 Nov 2024

    The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

    Published: 4 Dec 2023
    6.5
    Medium

    CVE-2023-5990

    Last Modified: 21 Nov 2024

    The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not have CSRF checks on some of its form actions such as deletion and duplication, which could allow attackers to make logged in admin perform such actions via CSRF attacks

    Published: 4 Dec 2023