2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-21021HIGH7.8In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin ...
CVE-2023-21017HIGH7.8In InstallStart of InstallStart.java, there is a possible way to change the installer package name due to an improper in...
CVE-2023-21015HIGH7.8In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis...
CVE-2023-21005HIGH7.8In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis...
CVE-2023-21004HIGH7.8In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis...
CVE-2023-21003HIGH7.8In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis...
CVE-2023-21002HIGH7.8In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a mis...
CVE-2023-21001HIGH7.8In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings...
CVE-2023-21000HIGH7.8In MediaCodec.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of pr...
CVE-2023-20995HIGH7.8In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error i...
CVE-2023-20993HIGH7.8In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to an uncaught exception...
CVE-2023-20985HIGH7.8In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input va...
CVE-2023-20976HIGH7.3In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default a...
CVE-2023-20975HIGH7.8In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CO...
CVE-2023-20971HIGH7.8In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions withou...
CVE-2023-20966HIGH7.8In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local...
CVE-2023-20964HIGH7.8In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This ...
CVE-2023-20963HIGH7.8In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional ...
CVE-2023-20960HIGH8.8In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities ...
CVE-2023-20959HIGH7.8In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks...
CVE-2023-20958HIGH7.1In read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to loca...
CVE-2023-20957HIGH7.8In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confuse...
CVE-2023-20955HIGH7.8In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and unins...
CVE-2023-20953HIGH7.8In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to bypass factory reset protection due to inc...
CVE-2023-20947HIGH7.8In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now