NA - CVE-2023-40109 - In createFromParcel of UsbConfiguration.java,...
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional...
NA - CVE-2023-40110 - In multiple functions of MtpPacket.cpp, there...
In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution...
NA - CVE-2023-40111 - In setMediaButtonReceiver of...
In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of...
NA - CVE-2023-40112 - In ippSetValueTag of ipp.c, there is a possible...
In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related...
NA - CVE-2023-40113 - In multiple locations, there is a possible way...
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional...
NA - CVE-2023-40114 - In multiple functions of MtpFfsHandle.cpp ,...
In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges...
NA - CVE-2023-40115 - In readLogs of StatsService.cpp, there is a...
In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User...
NA - CVE-2023-40124 - In multiple locations, there is a possible...
In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution...
NA - CVE-2024-23674 - The Online-Ausweis-Funktion eID scheme in the...
The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's...