Autore: Angelo Barbosa

CVE-2023-42570 | Samsung Smart Phone KnoxCustomManagerService permission

A vulnerability was found in Samsung Smart Phone and classified as critical. Affected by this issue is some unknown functionality of the component KnoxCustomManagerService. The manipulation leads to permission issues. This vulnerability is handled as CVE-2023-42570. The attack needs to be approached locally. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-40078 | Google Android 14 a2dp_vendor_opus_decoder.cc a2dp_vendor_opus_decoder_decode_packet out-of-bounds write

A vulnerability has been found in Google Android 14 and classified as critical. Affected by this vulnerability is the function a2dp_vendor_opus_decoder_decode_packet of the file a2dp_vendor_opus_decoder.cc. The manipulation leads to out-of-bounds write. This vulnerability is known as CVE-2023-40078. The attack can only be done within the local network. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più

CVE-2023-40084 | Google Android 11/12/12L/13/14 MDnsSdListener.cpp run use after free

A vulnerability, which was classified as problematic, was found in Google Android 11/12/12L/13/14. Affected is the function run of the file MDnsSdListener.cpp. The manipulation leads to use after free. This vulnerability is traded as CVE-2023-40084. Attacking locally is a requirement. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più

CVE-2023-40083 | Google Android 12/12L/13/14 utils.cc parse_gap_data information disclosure

A vulnerability, which was classified as problematic, has been found in Google Android 12/12L/13/14. This issue affects the function parse_gap_data of the file utils.cc. The manipulation leads to information disclosure. The identification of this vulnerability is CVE-2023-40083. Local access is required to approach this attack. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più

CVE-2023-40079 | Google Android 14 ShortcutService.java injectSendtentSender permission

A vulnerability classified as critical was found in Google Android 14. This vulnerability affects the function injectSendtentSender of the file ShortcutService.java. The manipulation leads to permission issues. This vulnerability was named CVE-2023-40079. An attack has to be approached locally. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più