Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-35689 In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default val… Android Mitigation only Fix from $1,9502023-08-14 CRITICAL 9.8 CVE-2023-21287 In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional executio… Android Patch available Fix from $2,3002023-08-14 HIGH 8.8 CVE-2023-21282 In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execut… Android Patch available Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21281 In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This c… Android Patch available Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21286 In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local e… Android Patch available Fix from $1,9502023-08-14 MEDIUM 5.5 CVE-2023-21277 In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local i… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21279 In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21280 In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21283 In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local i… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21284 In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input valid… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21285 In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local i… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21288 In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local … Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21289 In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information di… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21290 In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of s… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21292 In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. … Android Patch available Fix from $1,6002023-08-14 HIGH 8.8 CVE-2023-21273 In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjac… Android Patch available Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21231 In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected … Android Mitigation only Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21235 In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing PIN due to a permissions byp… Android Mitigation only Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21272 In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privil… Android Patch available Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21275 In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a lo… Android Patch available Fix from $1,9502023-08-14 HIGH 7.5 CVE-2023-21233 In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with… Android Mitigation only Fix from $1,9502023-08-14 MEDIUM 5.5 CVE-2023-21230 In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point c… Android Mitigation only Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21234 In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to… Android Mitigation only Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21271 In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local informatio… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21274 In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local inform… Android Patch available Fix from $1,6002023-08-14 MEDIUM 5.5 CVE-2023-21276 In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disc… Android Patch available Fix from $1,6002023-08-14 HIGH 7.8 CVE-2023-21229 In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingInten… Android Mitigation only Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21269 In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. Thi… Android Patch available Fix from $1,9502023-08-14 HIGH 7.5 CVE-2023-21265 In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional … Android Patch available Fix from $1,9502023-08-14 MEDIUM 5.5 CVE-2023-21267 In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the c… Android Mitigation only Fix from $1,6002023-08-14