2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21382MEDIUM5.5In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to...
CVE-2023-21381HIGH7.8In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. This could lead to ...
CVE-2023-21380MEDIUM6.7In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation...
CVE-2023-21379MEDIUM4.4In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information...
CVE-2023-21378HIGH7.8In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check....
CVE-2023-21377MEDIUM5.5In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local informat...
CVE-2023-21376MEDIUM5.5In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local i...
CVE-2023-21375HIGH7.8In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of...
CVE-2023-21374HIGH7.8In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to l...
CVE-2023-21373HIGH7.8In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. Th...
CVE-2023-21372HIGH7.8In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation...
CVE-2023-47090MEDIUM6.5NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authoriz...
CVE-2023-36920MEDIUM6.1In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X...
CVE-2023-21371MEDIUM6.7In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalati...
CVE-2023-21370MEDIUM6.7In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to loca...
CVE-2023-21369MEDIUM5.5In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissio...
CVE-2023-21368MEDIUM5.5In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information discl...
CVE-2023-21367MEDIUM5.5In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design...
CVE-2023-21366MEDIUM5.5In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/des...
CVE-2023-21365MEDIUM5.5In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in th...
CVE-2023-21364MEDIUM5.5In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent deni...
CVE-2023-21362MEDIUM5.5In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with ...
CVE-2023-21361HIGH8.8In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalat...
CVE-2023-21360MEDIUM6.7In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalat...
CVE-2023-21359MEDIUM4.4In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now