2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45776HIGH7.8In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This c...
CVE-2023-45775HIGH7.8In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This c...
CVE-2023-45774HIGH7.8In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's image due to a conf...
CVE-2023-45773HIGH7.8In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2023-40465MEDIUM5.5 Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be...
CVE-2023-40464MEDIUM6.8 Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An atta...
CVE-2023-40463HIGH7.2 When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and e...
CVE-2023-40462HIGH7.5The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which c...
CVE-2023-40461MEDIUM4.8 The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileg...
CVE-2023-40460MEDIUM5.4 The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which c...
CVE-2023-40459HIGH7.5 The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authen...
CVE-2023-40103HIGH7.8In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalati...
CVE-2023-40098MEDIUM5.5In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user...
CVE-2023-40097HIGH7.8In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation...
CVE-2023-40096HIGH7.8In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the backgroun...
CVE-2023-40095HIGH7.8In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due t...
CVE-2023-40094HIGH7.8In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permiss...
CVE-2023-40092MEDIUM5.5In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confu...
CVE-2023-40091HIGH7.8In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead ...
CVE-2023-40090MEDIUM6.5In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel info...
CVE-2023-40089HIGH7.8In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credent...
CVE-2023-40088HIGH8.8In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption du...
CVE-2023-40087HIGH8.8In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds chec...
CVE-2023-40084HIGH7.8In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local es...
CVE-2023-40083MEDIUM5.5In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now