|
219531
|
7.8 |
HIGH
Local
|
google
|
android
|
In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional executi…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2010
|
2024-11-21 13:40 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219532
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileg…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2009
|
2024-11-21 13:40 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219533
|
7.5 |
HIGH
Network
|
google
|
android
|
In createEffect of AudioFlinger.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
|
CWE-362 CWE-787
Race Condition Out-of-bounds Write
|
CVE-2019-2008
|
2024-11-21 13:40 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219534
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server w…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-2007
|
2024-11-21 13:40 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219535
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execu…
|
CWE-362 CWE-787 CWE-416
Race Condition Out-of-bounds Write Use After Free
|
CVE-2019-2006
|
2024-11-21 13:40 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219536
|
8.8 |
HIGH
Network
|
google
|
android
|
In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. This could lead to local escalation of privilege on …
|
CWE-862
Missing Authorization
|
CVE-2019-2005
|
2024-11-21 13:40 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219537
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privile…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-2004
|
2024-11-21 13:40 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219538
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8909w_firmware msm8996au_firmware qcs605_firmware qm215_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_427_firmware sd_430_firmware sd_43…
|
Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrag…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-2259
|
2024-11-21 13:40 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219539
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs405_firmware qcs605_firmware sd_210_firmware sd_212_firmware sd_205_firmware s…
|
Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-2257
|
2024-11-21 13:40 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219540
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware qm215_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_427_firmware sd_4…
|
An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT…
|
NVD-CWE-noinfo
|
CVE-2019-2256
|
2024-11-21 13:40 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|