Show filters
1,505 Total Results
Displaying 461-470 of 1,505
Sort by:
Attacker Value
Unknown

CVE-2023-40140

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40139

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40138

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40137

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40136

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40135

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40134

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40133

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40131

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2023-40130

Disclosure Date: October 27, 2023 (last updated October 31, 2023)
In onBindingDied of CallRedirectionProcessor.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.