Platform Packages Apps Car Settings vulnerabilities

4 known vulnerabilities affecting platform/packages_apps_car_settings.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN4

Vulnerabilities

Page 1 of 1
CVE-2023-21124UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21124 CVE-2023-21124: In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20350UNKNOWN≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20350 CVE-2022-20350: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39706UNKNOWN≥ 11:0, < 11:2022-03-01≥ 12:0, < 12:2022-03-01+1 more2022-03-01
CVE-2021-39706 CVE-2021-39706: In onResume of CredentialStorage In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0459UNKNOWN≥ 8.0:0, < 8.0:2020-12-01≥ 8.1:0, < 8.1:2020-12-01+2 more2020-12-01
CVE-2020-0459 CVE-2020-0459: In sendConfiguredNetworkChangedBroadcast of WifiConfigManager In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with no additional execution privileges needed. User interaction is not needed for exploitation.
osv