CVE-2023-21293
https://notcve.org/view.php?id=CVE-2023-21293
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. • https://source.android.com/docs/security/bulletin/android-14 • CWE-203: Observable Discrepancy •
CVE-2022-20264
https://notcve.org/view.php?id=CVE-2022-20264
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. • https://source.android.com/docs/security/bulletin/android-14 • CWE-203: Observable Discrepancy •
CVE-2023-43041 – IBM QRadar information disclosure
https://notcve.org/view.php?id=CVE-2023-43041
IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. • https://exchange.xforce.ibmcloud.com/vulnerabilities/266808 https://www.ibm.com/support/pages/node/7060803 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-40139
https://notcve.org/view.php?id=CVE-2023-40139
This could lead to local information disclosure with no additional execution privileges needed. • https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33 https://source.android.com/security/bulletin/2023-10-01 • CWE-610: Externally Controlled Reference to a Resource in Another Sphere •
CVE-2023-40138
https://notcve.org/view.php?id=CVE-2023-40138
This could lead to local information disclosure with no additional execution privileges needed. • https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33 https://source.android.com/security/bulletin/2023-10-01 •