CVE-2019-2193
- EPSS 0.01%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:24
In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privilege, leaving an Admin app installed with no indication to the user, wi...
CVE-2019-2195
- EPSS 0.03%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:24
In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...
CVE-2019-2196
- EPSS 0.69%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:24
In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 A...
CVE-2019-2197
- EPSS 0.02%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:24
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no additional execution privileges needed...
CVE-2019-2198
- EPSS 0.69%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8...
CVE-2019-2199
- EPSS 0.01%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Andro...
CVE-2019-2201
- EPSS 1.08%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. U...
CVE-2019-2202
- EPSS 0.04%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVE-2019-2203
- EPSS 0.04%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
- EPSS 1.25%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This could lead to remote code execution in the pacprocessor with no additional execution privileges needed. User interaction is not ne...