2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21288MEDIUM5.5In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission che...
CVE-2023-21287CRITICAL9.8In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code executio...
CVE-2023-21286HIGH7.8In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission chec...
CVE-2023-21285MEDIUM5.5In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deput...
CVE-2023-21284MEDIUM5.5In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device featur...
CVE-2023-21283MEDIUM5.5In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deput...
CVE-2023-21282HIGH8.8In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This cou...
CVE-2023-21281HIGH7.8In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a lo...
CVE-2023-21280MEDIUM5.5In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaust...
CVE-2023-21279MEDIUM5.5In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to...
CVE-2023-21278LOW3.3In multiple locations, there is a possible way to obscure the microphone privacy indicator due to a logic error in the c...
CVE-2023-21277MEDIUM5.5In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission chec...
CVE-2023-21276MEDIUM5.5In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could l...
CVE-2023-21275HIGH7.8In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory ...
CVE-2023-21274MEDIUM5.5In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2023-21273HIGH8.8In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could l...
CVE-2023-21272HIGH7.8In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead ...
CVE-2023-21271MEDIUM5.5In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This c...
CVE-2023-21235HIGH7.8In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing...
CVE-2023-21234MEDIUM5.5In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options with...
CVE-2023-21233HIGH7.5In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remot...
CVE-2023-21232LOW3.3In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. ...
CVE-2023-21231HIGH7.8In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-expo...
CVE-2023-21230MEDIUM5.5In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadc...
CVE-2023-21229HIGH7.8In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now