CVE-2023-33906
https://notcve.org/view.php?id=CVE-2023-33906
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges • https://www.unisoc.com/en_us/secy/announcementDetail/https://www.unisoc.com/en_us/secy/announcementDetail/1687281677639942145 • CWE-862: Missing Authorization •
CVE-2022-48451
https://notcve.org/view.php?id=CVE-2022-48451
In bluetooth service, there is a possible out of bounds write due to race condition. This could lead to local denial of service with System execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1676902764208259073 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2023-33905
https://notcve.org/view.php?id=CVE-2023-33905
In iwnpi server, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1676902764208259073 • CWE-787: Out-of-bounds Write •
CVE-2023-33904
https://notcve.org/view.php?id=CVE-2023-33904
In hci_server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1676902764208259073 • CWE-125: Out-of-bounds Read •
CVE-2022-48450
https://notcve.org/view.php?id=CVE-2022-48450
In bluetooth service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1676902764208259073 •