2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21382 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to... |
| CVE-2023-21381 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. This could lead to ... |
| CVE-2023-21380 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation... |
| CVE-2023-21379 | MEDIUM | 4.4 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information... |
| CVE-2023-21378 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check.... |
| CVE-2023-21377 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In SELinux Policy, there is a possible restriction bypass due to a permissions bypass. This could lead to local informat... |
| CVE-2023-21376 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local i... |
| CVE-2023-21375 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of... |
| CVE-2023-21374 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to l... |
| CVE-2023-21373 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. Th... |
| CVE-2023-21372 | HIGH | 7.8 | 0.1% | Oct 30, 2023 | In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation... |
| CVE-2023-47090 | MEDIUM | 6.5 | 0.7% | Oct 30, 2023 | NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authoriz... |
| CVE-2023-36920 | MEDIUM | 6.1 | 0.3% | Oct 30, 2023 | In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X... |
| CVE-2023-21371 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalati... |
| CVE-2023-21370 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to loca... |
| CVE-2023-21369 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissio... |
| CVE-2023-21368 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information discl... |
| CVE-2023-21367 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design... |
| CVE-2023-21366 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/des... |
| CVE-2023-21365 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in th... |
| CVE-2023-21364 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent deni... |
| CVE-2023-21362 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with ... |
| CVE-2023-21361 | HIGH | 8.8 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalat... |
| CVE-2023-21360 | MEDIUM | 6.7 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalat... |
| CVE-2023-21359 | MEDIUM | 4.4 | 0.1% | Oct 30, 2023 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now