Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2023-35689

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default val…

Mitigation only
Fix from $1,950 2023-08-14
Android CRITICAL 9.8
CVE-2023-21287

In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional executio…

Patch available
Fix from $2,300 2023-08-14
Android HIGH 8.8
CVE-2023-21282

In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execut…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21281

In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This c…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21286

In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local e…

Patch available
Fix from $1,950 2023-08-14
Android MEDIUM 5.5
CVE-2023-21277

In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local i…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21279

In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21280

In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21283

In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local i…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21284

In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input valid…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21285

In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local i…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21288

In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local …

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21289

In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information di…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21290

In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of s…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21292

In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. …

Patch available
Fix from $1,600 2023-08-14
Android HIGH 8.8
CVE-2023-21273

In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjac…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21231

In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected …

Mitigation only
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21235

In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing PIN due to a permissions byp…

Mitigation only
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21272

In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privil…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21275

In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a lo…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.5
CVE-2023-21233

In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with…

Mitigation only
Fix from $1,950 2023-08-14
Android MEDIUM 5.5
CVE-2023-21230

In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point c…

Mitigation only
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21234

In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to…

Mitigation only
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21271

In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local informatio…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21274

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local inform…

Patch available
Fix from $1,600 2023-08-14
Android MEDIUM 5.5
CVE-2023-21276

In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disc…

Patch available
Fix from $1,600 2023-08-14
Android HIGH 7.8
CVE-2023-21229

In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingInten…

Mitigation only
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21269

In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. Thi…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.5
CVE-2023-21265

In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional …

Patch available
Fix from $1,950 2023-08-14
Android MEDIUM 5.5
CVE-2023-21267

In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the c…

Mitigation only
Fix from $1,600 2023-08-14