Lucene search

K

Android Security Vulnerabilities

cve
cve

CVE-2023-40639

In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
16
cve
cve

CVE-2023-40640

In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
25
cve
cve

CVE-2023-40641

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
14
cve
cve

CVE-2023-40642

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
21
cve
cve

CVE-2023-40643

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
14
cve
cve

CVE-2023-40644

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
24
cve
cve

CVE-2023-40645

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
20
cve
cve

CVE-2023-40646

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
22
cve
cve

CVE-2023-40647

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
20
cve
cve

CVE-2023-40648

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
25
cve
cve

CVE-2023-40649

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
24
cve
cve

CVE-2023-40650

In Telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-10-08 04:15 AM
16
cve
cve

CVE-2023-40651

In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

4.4CVSS

4.8AI Score

0.0004EPSS

2023-10-08 04:15 AM
17
cve
cve

CVE-2023-40652

In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

4.4CVSS

4.8AI Score

0.0004EPSS

2023-10-08 04:15 AM
33
cve
cve

CVE-2023-40653

In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

6.7CVSS

6.7AI Score

0.0004EPSS

2023-10-08 04:15 AM
19
cve
cve

CVE-2023-40654

In FW-PackageManager, there is a possible missing permission check. This could lead to local escalation of privilege with System execution privileges needed

6.7CVSS

6.7AI Score

0.0004EPSS

2023-10-08 04:15 AM
18
cve
cve

CVE-2023-4164

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.

8.4CVSS

5.4AI Score

0.0004EPSS

2024-01-02 10:15 PM
17
cve
cve

CVE-2023-42527

Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.

5.6CVSS

5.3AI Score

0.0004EPSS

2023-11-07 08:15 AM
10
cve
cve

CVE-2023-42528

Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

7.8CVSS

7.7AI Score

0.0004EPSS

2023-11-07 08:15 AM
11
cve
cve

CVE-2023-42529

Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.

7.8CVSS

7.7AI Score

0.0004EPSS

2023-11-07 08:15 AM
11
cve
cve

CVE-2023-42530

Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.

7.5CVSS

7.4AI Score

0.0005EPSS

2023-11-07 08:15 AM
8
cve
cve

CVE-2023-42531

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

7.1CVSS

6.7AI Score

0.0004EPSS

2023-11-07 08:15 AM
30
cve
cve

CVE-2023-42532

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

7.5CVSS

7.5AI Score

0.001EPSS

2023-11-07 08:15 AM
13
cve
cve

CVE-2023-42533

Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.

6.8CVSS

6.7AI Score

0.001EPSS

2023-11-07 08:15 AM
7
cve
cve

CVE-2023-42534

Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.

6.3CVSS

5.3AI Score

0.0004EPSS

2023-11-07 08:15 AM
13
cve
cve

CVE-2023-42535

Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

8.4CVSS

7.7AI Score

0.0004EPSS

2023-11-07 08:15 AM
13
cve
cve

CVE-2023-42536

An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

8.4CVSS

7.3AI Score

0.0004EPSS

2023-11-07 08:15 AM
32
cve
cve

CVE-2023-42537

An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

8.4CVSS

7.3AI Score

0.0004EPSS

2023-11-07 08:15 AM
29
cve
cve

CVE-2023-42538

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

7.8CVSS

7.3AI Score

0.0004EPSS

2023-11-07 08:15 AM
32
cve
cve

CVE-2023-42556

Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

5.5CVSS

5.4AI Score

0.001EPSS

2023-12-05 03:15 AM
11
cve
cve

CVE-2023-42557

Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.

6.7CVSS

6.7AI Score

0.0004EPSS

2023-12-05 03:15 AM
11
cve
cve

CVE-2023-42558

Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.

7.8CVSS

7.8AI Score

0.0004EPSS

2023-12-05 03:15 AM
11
cve
cve

CVE-2023-42559

Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.

5.2CVSS

5.2AI Score

0.001EPSS

2023-12-05 03:15 AM
13
cve
cve

CVE-2023-42560

Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.

7.8CVSS

7.9AI Score

0.0004EPSS

2023-12-05 03:15 AM
10
cve
cve

CVE-2023-42561

Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

7.1CVSS

6.8AI Score

0.001EPSS

2023-12-05 03:15 AM
10
cve
cve

CVE-2023-42562

Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

7.8CVSS

7.6AI Score

0.0004EPSS

2023-12-05 03:15 AM
11
cve
cve

CVE-2023-42563

Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

7.8CVSS

7.6AI Score

0.0004EPSS

2023-12-05 03:15 AM
8
cve
cve

CVE-2023-42564

Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.

6.6CVSS

5.4AI Score

0.0004EPSS

2023-12-05 03:15 AM
16
cve
cve

CVE-2023-42565

Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.

7.3CVSS

6.7AI Score

0.0004EPSS

2023-12-05 03:15 AM
11
cve
cve

CVE-2023-42566

Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

7.8CVSS

7.7AI Score

0.0004EPSS

2023-12-05 03:15 AM
15
cve
cve

CVE-2023-42567

Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

7.8CVSS

7.6AI Score

0.0004EPSS

2023-12-05 03:15 AM
12
cve
cve

CVE-2023-42568

Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

7.3CVSS

4.7AI Score

0.0004EPSS

2023-12-05 03:15 AM
10
cve
cve

CVE-2023-42569

Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.

4CVSS

4.1AI Score

0.0004EPSS

2023-12-05 03:15 AM
7
cve
cve

CVE-2023-42570

Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.

5.9CVSS

4.1AI Score

0.0004EPSS

2023-12-05 03:15 AM
22
cve
cve

CVE-2023-42631

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-11-01 10:15 AM
15
cve
cve

CVE-2023-42632

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-11-01 10:15 AM
19
cve
cve

CVE-2023-42633

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-11-01 10:15 AM
13
cve
cve

CVE-2023-42634

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-11-01 10:15 AM
11
cve
cve

CVE-2023-42635

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-11-01 10:15 AM
14
cve
cve

CVE-2023-42636

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

5.5CVSS

5.2AI Score

0.0004EPSS

2023-11-01 10:15 AM
23
Total number of security vulnerabilities7167