CVE-2023-21173
https://notcve.org/view.php?id=CVE-2023-21173
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262741858 • https://source.android.com/security/bulletin/pixel/2023-06-01 • CWE-862: Missing Authorization •
CVE-2023-21512
https://notcve.org/view.php?id=CVE-2023-21512
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=06 • CWE-269: Improper Privilege Management CWE-276: Incorrect Default Permissions •
CVE-2023-21176
https://notcve.org/view.php?id=CVE-2023-21176
In list_key_entries of utils.rs, there is a possible way to disable user credentials due to resource exhaustion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222287335 • https://source.android.com/security/bulletin/pixel/2023-06-01 • CWE-400: Uncontrolled Resource Consumption •
CVE-2023-21190
https://notcve.org/view.php?id=CVE-2023-21190
In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251436534 • https://source.android.com/security/bulletin/pixel/2023-06-01 •
CVE-2023-21212
https://notcve.org/view.php?id=CVE-2023-21212
In multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236031 • https://source.android.com/security/bulletin/pixel/2023-06-01 • CWE-125: Out-of-bounds Read •