|
224411
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User intera…
|
NVD-CWE-noinfo
|
CVE-2019-2199
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224412
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f…
|
CWE-89
SQL Injection
|
CVE-2019-2198
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224413
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact …
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-2197
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224414
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.…
|
CWE-89
SQL Injection
|
CVE-2019-2196
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224415
|
7.8 |
HIGH
Local
|
google
|
android
|
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional exec…
|
CWE-20 CWE-89
Improper Input Validation SQL Injection
|
CVE-2019-2195
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224416
|
7.8 |
HIGH
Local
|
google
|
android
|
In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privilege, leaving an Adm…
|
CWE-269
Improper Privilege Management
|
CVE-2019-2193
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224417
|
7.8 |
HIGH
Local
|
google
|
android
|
In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed…
|
CWE-20
Improper Input Validation
|
CVE-2019-2192
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224418
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could lead to remote escalation of privilege with no additional execution privileges…
|
NVD-CWE-noinfo
|
CVE-2019-2036
|
2024-11-21 13:40 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224419
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9615_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs405_firmware qcs605_firmware
|
Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-2332
|
2024-11-21 13:40 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224420
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9615_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs405_firmware qcs605_firmware
|
Possible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industri…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-2331
|
2024-11-21 13:40 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|