|
221141
|
7.8 |
HIGH
Local
|
google
|
android
|
In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of privilege with no additional execution privileges …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-2089
|
2024-11-21 13:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221142
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were not enabled, with no additional execution privileges needed. User interaction is…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-2088
|
2024-11-21 13:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221143
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no additional execution privileges needed. User interaction is needed for exploitation.Pro…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-2058
|
2024-11-21 13:40 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221144
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8905_firmware msm8909_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware msm8953_firmware nicobar_firmware qcm2150_firmware qm215_firmware s…
|
The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be predicted in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Sna…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-2317
|
2024-11-21 13:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221145
|
9.8 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8096_firmware apq8096au_firmware apq8098_firmware ipq8074_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware mdm9640_firmware…
|
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer El…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-2311
|
2024-11-21 13:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221146
|
9.8 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8096_firmware apq8098_firmware ipq8074_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware msm8996_firmware
|
Possible buffer overflow in WLAN handler due to lack of validation of destination buffer size before copying into it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consum…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-2300
|
2024-11-21 13:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221147
|
7.3 |
HIGH
Local
|
google
|
android
|
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escal…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-2200
|
2024-11-21 13:40 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221148
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9205_firmware qcs404_firmware qcs605_firmware sda845_firmware sdm670_firmware sdm710_firmware sdm845_firmware sdm850_firmware sm8150_firmware sxr1130_firmware sxr2130…
|
Locked regions may be modified through other interfaces in secure boot loader image due to improper access control. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consume…
|
NVD-CWE-Other
|
CVE-2019-2267
|
2024-11-21 13:40 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221149
|
7.8 |
HIGH
Local
|
qualcomm
|
ipq4019_firmware ipq8064_firmware ipq8074_firmware mdm9607_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware qcn7605_firmware qcs405_firmware …
|
Integer overflow to buffer overflow due to lack of validation of event arguments received from firmware. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Sna…
|
CWE-20 CWE-787 CWE-190
Improper Input Validation Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-2304
|
2024-11-21 13:40 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221150
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8017_firmware apq8053_firmware apq8098_firmware ipq8074_firmware mdm9150_firmware mdm9650_firmware mdm9655_firmware msm8917_firmware msm8920_firmware msm8937_firmware
|
Improper Access Control for RPU write access from secure processor in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…
|
NVD-CWE-noinfo
|
CVE-2019-2274
|
2024-11-21 13:40 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|