|
221311
|
8.8 |
HIGH
Network
|
google
|
android
|
In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due to a permissions bypass. This could lead to remote code execution with no addi…
|
CWE-275
Permission Issues
|
CVE-2019-2177
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221312
|
7.8 |
HIGH
Local
|
google
|
android
|
In ihevcd_parse_buffering_period_sei of ihevcd_parse_headers.c in Android 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executi…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2176
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221313
|
7.8 |
HIGH
Local
|
google
|
android
|
In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of privilege with no add…
|
CWE-863
Incorrect Authorization
|
CVE-2019-2175
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221314
|
7.8 |
HIGH
Local
|
google
|
android
|
In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of p…
|
CWE-416 CWE-667
Use After Free Improper Locking
|
CVE-2019-2174
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221315
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In ComposeActivityEmailExternal of ComposeActivityEmailExternal.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible way to silently attach files to an email due to a confused deputy. Th…
|
NVD-CWE-noinfo
|
CVE-2019-2124
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221316
|
7.8 |
HIGH
Local
|
google
|
android
|
In execTransact of Binder.java in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible local execution of arbitrary code in a privileged process due to a memory overwrite. This could lead to lo…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2123
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221317
|
7.8 |
HIGH
Local
|
google
|
android
|
In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with…
|
CWE-787 CWE-415
Out-of-bounds Write Double Free
|
CVE-2019-2115
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221318
|
7.8 |
HIGH
Local
|
google
|
android
|
In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution pri…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2108
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221319
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with …
|
CWE-200
Information Exposure
|
CVE-2019-2103
|
2024-11-21 13:40 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221320
|
7.8 |
HIGH
Local
|
mongodb
|
mongodb
|
An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined c…
|
NVD-CWE-noinfo
|
CVE-2019-2390
|
2024-11-21 13:40 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|