|
219351
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9205_firmware mdm9206_firmware mdm9607_firmware mdm9615_firmware mdm9625_firmware mdm9635m_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware…
|
Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivi…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-2294
|
2024-11-21 13:40 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219352
|
7.0 |
HIGH
Local
|
qualcomm
|
msm8909w_firmware qcs405_firmware qcs605_firmware qualcomm_215_firmware sd_425_firmware sd_439_firmware sd_429_firmware sd_450_firmware sd_625_firmware sd_632_firmware s…
|
Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-2284
|
2024-11-21 13:40 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219353
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware qualcomm_215_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_427_firmware<…
|
Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Con…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-2252
|
2024-11-21 13:40 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219354
|
4.3 |
MEDIUM
Physics
|
google
|
android
|
In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-2191
|
2024-11-21 13:40 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219355
|
4.3 |
MEDIUM
Physics
|
google
|
android
|
In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-2190
|
2024-11-21 13:40 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219356
|
6.4 |
MEDIUM
Local
|
google
|
android
|
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not need…
|
CWE-362 CWE-787
Race Condition Out-of-bounds Write
|
CVE-2019-2189
|
2024-11-21 13:40 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219357
|
6.4 |
MEDIUM
Local
|
google
|
android
|
In the Easel driver, there is possible memory corruption due to race conditions. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not need…
|
CWE-362 CWE-787
Race Condition Out-of-bounds Write
|
CVE-2019-2188
|
2024-11-21 13:40 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219358
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed f…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-2172
|
2024-11-21 13:40 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219359
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed f…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-2171
|
2024-11-21 13:40 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219360
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed f…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-2170
|
2024-11-21 13:40 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|