CVE Severity Distribution (Last 30 Days)
Found 10 CVEs in the last 30 days.
CVE-2023-2136
CRITICAL
CVSS: 9.6
EPSS: 5.7%
VulnCheck KEV
PoC Available
CWE-190
CWE-190
T1203
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2023-04-19
CVE-2023-21361
HIGH
CVSS: 8.8
EPSS: 0.1%
CWE-416
T1203
In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalation of privilege in the privileged Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21360
MEDIUM
CVSS: 6.7
EPSS: 0.1%
CWE-787
T1203
In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21362
MEDIUM
CVSS: 5.5
EPSS: 0.1%
In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21364
MEDIUM
CVSS: 5.5
EPSS: 0.1%
In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21365
MEDIUM
CVSS: 5.5
EPSS: 0.1%
In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in the Phone app with User execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21366
MEDIUM
CVSS: 5.5
EPSS: 0.1%
In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21367
MEDIUM
CVSS: 5.5
EPSS: 0.1%
In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21368
MEDIUM
CVSS: 5.5
EPSS: 0.1%
CWE-125
T1005
In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2023-10-30
CVE-2023-21369
MEDIUM
CVSS: 5.5
EPSS: 0.1%
In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Published: 2023-10-30