10
CVE-2019-20607
- EPSS 0.23%
- Veröffentlicht 24.03.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 04:38:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998, Exynos7420, Exynos7870, Exynos8890, and Exynos8895 chipsets) software. A heap overflow in the keymaster Trustlet allows attackers to write to TEE memory, and achieve arbitrary code execution. The Samsung ID is SVE-2019-14126 (May 2019).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version7.0
Qualcomm ≫ Msm8996 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Google ≫ Android Version7.1.0
Qualcomm ≫ Msm8996 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Google ≫ Android Version7.1.1
Qualcomm ≫ Msm8996 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Google ≫ Android Version7.1.2
Qualcomm ≫ Msm8996 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Google ≫ Android Version8.0
Qualcomm ≫ Msm8996 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Google ≫ Android Version8.1
Qualcomm ≫ Msm8996 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Google ≫ Android Version9.0
Qualcomm ≫ Msm8996 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
Qualcomm ≫ Msm8998 Version-
Samsung ≫ Exynos 7420 Version-
Samsung ≫ Exynos 7870 Version-
Samsung ≫ Exynos 8890 Version-
Samsung ≫ Exynos 8895 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.429 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.