|
221101
|
8.8 |
HIGH
Network
|
google
|
android
|
In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileg…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2206
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221102
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileg…
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2019-2205
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221103
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This could lead to remote code execution in the pacprocessor with no additional exec…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-2204
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221104
|
7.8 |
HIGH
Local
|
google
|
android
|
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution priv…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2203
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221105
|
7.8 |
HIGH
Local
|
google
|
android
|
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution priv…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2202
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221106
|
7.8 |
HIGH
Local
|
google canonical
|
android ubuntu_linux
|
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2201
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221107
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User intera…
|
NVD-CWE-noinfo
|
CVE-2019-2199
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221108
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f…
|
CWE-89
SQL Injection
|
CVE-2019-2198
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221109
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact …
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-2197
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221110
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.…
|
CWE-89
SQL Injection
|
CVE-2019-2196
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|