CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2023-21367

    Last Modified: 21 Nov 2024

    In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21366

    Last Modified: 21 Nov 2024

    In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21365

    Last Modified: 21 Nov 2024

    In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21364

    Last Modified: 21 Nov 2024

    In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21362

    Last Modified: 21 Nov 2024

    In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    8.8
    High

    CVE-2023-21361

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalation of privilege in the privileged Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    6.7
    Medium

    CVE-2023-21360

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    4.4
    Medium

    CVE-2023-21359

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21358

    Last Modified: 30 Apr 2025

    In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    4.4
    Medium

    CVE-2023-21357

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    8.8
    High

    CVE-2023-21356

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21355

    Last Modified: 21 Nov 2024

    In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21354

    Last Modified: 21 Nov 2024

    In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.5
    High

    CVE-2023-21353

    Last Modified: 21 Nov 2024

    In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21352

    Last Modified: 21 Nov 2024

    In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21351

    Last Modified: 21 Nov 2024

    In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21350

    Last Modified: 21 Nov 2024

    In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    3.3
    Low

    CVE-2023-21349

    Last Modified: 21 Nov 2024

    In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    3.3
    Low

    CVE-2023-21348

    Last Modified: 21 Nov 2024

    In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.5
    High

    CVE-2023-21347

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    3.3
    Low

    CVE-2023-21346

    Last Modified: 21 Nov 2024

    In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    3.3
    Low

    CVE-2023-21345

    Last Modified: 21 Nov 2024

    In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21344

    Last Modified: 21 Nov 2024

    In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21343

    Last Modified: 21 Nov 2024

    In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21342

    Last Modified: 30 Sept 2025

    In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21341

    Last Modified: 21 Nov 2024

    In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21340

    Last Modified: 21 Nov 2024

    In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.5
    High

    CVE-2023-21339

    Last Modified: 21 Nov 2024

    In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21338

    Last Modified: 21 Nov 2024

    In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21337

    Last Modified: 21 Nov 2024

    In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21336

    Last Modified: 21 Nov 2024

    In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21335

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21334

    Last Modified: 21 Nov 2024

    In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21333

    Last Modified: 21 Nov 2024

    In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21332

    Last Modified: 21 Nov 2024

    In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21331

    Last Modified: 21 Nov 2024

    In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21330

    Last Modified: 21 Nov 2024

    In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21329

    Last Modified: 21 Nov 2024

    In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21328

    Last Modified: 21 Nov 2024

    In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21327

    Last Modified: 21 Nov 2024

    In Permission Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21326

    Last Modified: 21 Nov 2024

    In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21325

    Last Modified: 21 Nov 2024

    In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    7.8
    High

    CVE-2023-21324

    Last Modified: 21 Nov 2024

    In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21323

    Last Modified: 21 Nov 2024

    In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21321

    Last Modified: 21 Nov 2024

    In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21320

    Last Modified: 21 Nov 2024

    In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21319

    Last Modified: 21 Nov 2024

    In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21318

    Last Modified: 21 Nov 2024

    In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21317

    Last Modified: 21 Nov 2024

    In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023
    5.5
    Medium

    CVE-2023-21316

    Last Modified: 21 Nov 2024

    In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 30 Oct 2023