2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21384 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to l... |
| CVE-2023-21383 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This coul... |
| CVE-2023-21382 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to... |
| CVE-2023-21380 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation... |
| CVE-2023-21379 | MEDIUM | 4.4 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information... |
| CVE-2023-21377 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local informat... |
| CVE-2023-21376 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local i... |
| CVE-2023-47090 | MEDIUM | 6.5 | 0.7% | Oct 30, 2023 | NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authoriz... |
| CVE-2023-36920 | MEDIUM | 6.1 | 0.3% | Oct 30, 2023 | In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X... |
| CVE-2023-21371 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalati... |
| CVE-2023-21370 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to loca... |
| CVE-2023-21369 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissio... |
| CVE-2023-21368 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information discl... |
| CVE-2023-21367 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design... |
| CVE-2023-21366 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/des... |
| CVE-2023-21365 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in th... |
| CVE-2023-21364 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent deni... |
| CVE-2023-21362 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with ... |
| CVE-2023-21360 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalat... |
| CVE-2023-21359 | MEDIUM | 4.4 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information... |
| CVE-2023-21357 | MEDIUM | 4.4 | 0.1% | Oct 30, 2023 | In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl... |
| CVE-2023-21354 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions,... |
| CVE-2023-21352 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl... |
| CVE-2023-21350 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to... |
| CVE-2023-21344 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to si... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now