2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45776 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This c... |
| CVE-2023-45775 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This c... |
| CVE-2023-45774 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's image due to a conf... |
| CVE-2023-45773 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2023-40465 | MEDIUM | 5.5 | 0.2% | Dec 4, 2023 | Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be... |
| CVE-2023-40464 | MEDIUM | 6.8 | 0.3% | Dec 4, 2023 | Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An atta... |
| CVE-2023-40463 | HIGH | 7.2 | 0.6% | Dec 4, 2023 | When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and e... |
| CVE-2023-40462 | HIGH | 7.5 | 0.9% | Dec 4, 2023 | The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which c... |
| CVE-2023-40461 | MEDIUM | 4.8 | 0.5% | Dec 4, 2023 | The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileg... |
| CVE-2023-40460 | MEDIUM | 5.4 | 0.5% | Dec 4, 2023 | The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which c... |
| CVE-2023-40459 | HIGH | 7.5 | 2.3% | Dec 4, 2023 | The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authen... |
| CVE-2023-40103 | HIGH | 7.8 | 0.2% | Dec 4, 2023 | In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalati... |
| CVE-2023-40098 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user... |
| CVE-2023-40097 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation... |
| CVE-2023-40096 | HIGH | 7.8 | 0.2% | Dec 4, 2023 | In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the backgroun... |
| CVE-2023-40095 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due t... |
| CVE-2023-40094 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permiss... |
| CVE-2023-40092 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confu... |
| CVE-2023-40091 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead ... |
| CVE-2023-40090 | MEDIUM | 6.5 | 0.5% | Dec 4, 2023 | In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel info... |
| CVE-2023-40089 | HIGH | 7.8 | 0.1% | Dec 4, 2023 | In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credent... |
| CVE-2023-40088 | HIGH | 8.8 | 1.7% | Dec 4, 2023 | In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption du... |
| CVE-2023-40087 | HIGH | 8.8 | 0.2% | Dec 4, 2023 | In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds chec... |
| CVE-2023-40084 | HIGH | 7.8 | 0.2% | Dec 4, 2023 | In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local es... |
| CVE-2023-40083 | MEDIUM | 5.5 | 0.1% | Dec 4, 2023 | In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now