|
221761
|
7.8 |
HIGH
Local
|
google
|
android
|
n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privile…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2222
|
2024-11-21 13:40 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221762
|
7.8 |
HIGH
Local
|
google
|
android
|
In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could le…
|
NVD-CWE-noinfo
|
CVE-2019-2221
|
2024-11-21 13:40 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221763
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling application suspend. This could lead to local information disclosure no additio…
|
NVD-CWE-noinfo
|
CVE-2019-2220
|
2024-11-21 13:40 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221764
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from the background without notification to the user due to a permission bypass. Thi…
|
CWE-362
Race Condition
|
CVE-2019-2219
|
2024-11-21 13:40 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221765
|
7.8 |
HIGH
Local
|
google
|
android
|
In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of privilege by installi…
|
CWE-862
Missing Authorization
|
CVE-2019-2218
|
2024-11-21 13:40 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221766
|
7.8 |
HIGH
Local
|
google
|
android
|
In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2019-2217
|
2024-11-21 13:40 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221767
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9205_firmware qcs404_firmware qcs605_firmware sda845_firmware sdm670_firmware sdm710_firmware sdm845_firmware sdm850_firmware sdx24_firmware sdx55_firmware sm6150_fir…
|
Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapd…
|
CWE-129
Improper Validation of Array Index
|
CVE-2019-2339
|
2024-11-21 13:40 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221768
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9205_firmware qcs404_firmware sdx55_firmware sm6150_firmware sm7150_firmware sm8150_firmware sxr2130_firmware
|
Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapd…
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2019-2336
|
2024-11-21 13:40 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221769
|
7.5 |
HIGH
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8096au_firmware apq8098_firmware mdm9150_firmware mdm9205_firmware mdm9206_firmware mdm9607_firmware mdm9615_firmware<…
|
While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-2335
|
2024-11-21 13:40 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221770
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9205_firmware qcs404_firmware qcs605_firmware sda845_firmware sdm670_firmware sdm710_firmware sdm845_firmware sdx55_firmware sm6150_firmware sm7150_firmware sm8150_fi…
|
Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application. in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna…
|
CWE-416
Use After Free
|
CVE-2019-2329
|
2024-11-21 13:40 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|