|
221381
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9150_firmware mdm9650_firmware msm8996au_firmware qcs405_firmware qcs605_firmware sd_625_firmware sd_636_firmware sd_665_firmware sd_712_firmware sd_710_firmware sd_6…
|
Possible buffer overflow while processing the high level lim process action frame due to improper buffer length validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-2269
|
2024-11-21 13:40 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221382
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9607_firmware mdm9640_firmware msm8909w_firmware qcs405_firmware qcs605_firmware sd_425_firmware sd_427_firmware sd_430_firmware sd_435_firmware sd_439_firmware sd_42…
|
Null pointer dereference occurs for channel context while opening glink channel in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM96…
|
CWE-476 CWE-416
NULL Pointer Dereference Use After Free
|
CVE-2019-2264
|
2024-11-21 13:40 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221383
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ipq8074_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8996au_firmware qca8081_firmware qcs605_firmware qualcomm_215_firmware sd_210_firmwa…
|
Unauthorized access from GPU subsystem to HLOS or other non secure subsystem memory can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Cons…
|
NVD-CWE-noinfo
|
CVE-2019-2261
|
2024-11-21 13:40 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221384
|
7.0 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware qcs405_firmware qcs605_firmware qualcomm_215_firmware sd_210_firmware…
|
A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-2260
|
2024-11-21 13:40 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221385
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware s…
|
Possible buffer overflow at the end of iterating loop while getting the version info and lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon In…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-2243
|
2024-11-21 13:40 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221386
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additiona…
|
CWE-667
Improper Locking
|
CVE-2019-2119
|
2024-11-21 13:40 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221387
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead to local information disclosure with no additional execution privileges needed. …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-2118
|
2024-11-21 13:40 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221388
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead to local information disclosure about carrier syste…
|
CWE-862
Missing Authorization
|
CVE-2019-2117
|
2024-11-21 13:40 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221389
|
7.5 |
HIGH
Network
|
google
|
android
|
In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges nee…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-2116
|
2024-11-21 13:40 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221390
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset protection bypass with no additional privileges needed. User interaction is not need…
|
NVD-CWE-noinfo
|
CVE-2019-2113
|
2024-11-21 13:40 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|