|
221731
|
5.5 |
MEDIUM
Local
|
google
|
android
|
There is a possible disclosure of RAM using a shared crypto key due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User int…
|
NVD-CWE-noinfo
|
CVE-2019-2056
|
2024-11-21 13:40 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221732
|
5.4 |
MEDIUM
Network
|
mongodb
|
js-bson
|
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB In…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-2391
|
2024-11-21 13:40 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221733
|
7.3 |
HIGH
Local
|
google
|
android
|
In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privilege because the user is not notified of an overlayin…
|
CWE-20
Improper Input Validation
|
CVE-2019-2216
|
2024-11-21 13:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221734
|
7.8 |
HIGH
Local
|
google
|
android
|
In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of privilege with no additional execution privileges …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-2089
|
2024-11-21 13:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221735
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were not enabled, with no additional execution privileges needed. User interaction is…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-2088
|
2024-11-21 13:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221736
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no additional execution privileges needed. User interaction is needed for exploitation.Pro…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-2058
|
2024-11-21 13:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221737
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8905_firmware msm8909_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware msm8953_firmware nicobar_firmware qcm2150_firmware qm215_firmware s…
|
The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be predicted in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Sna…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-2317
|
2024-11-21 13:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221738
|
9.8 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8096_firmware apq8096au_firmware apq8098_firmware ipq8074_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware mdm9640_firmware…
|
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer El…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-2311
|
2024-11-21 13:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221739
|
9.8 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8096_firmware apq8098_firmware ipq8074_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware msm8996_firmware
|
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying into it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consum…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-2300
|
2024-11-21 13:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221740
|
7.3 |
HIGH
Local
|
google
|
android
|
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escal…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-2200
|
2024-11-21 13:40 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|