CVE-2019-2022
- EPSS 0.13%
- Veröffentlicht 19.06.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:40:05
In rw_t3t_act_handle_fmt_rsp and rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interac...
CVE-2019-2023
- EPSS 0.22%
- Veröffentlicht 19.06.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:40:05
In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could allow an app to add or replace a HAL service with its own service, gaining code execution in a privileg...
CVE-2019-2024
- EPSS 0.09%
- Veröffentlicht 19.06.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:40:05
In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use after free issue. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVE-2019-2025
- EPSS 0.25%
- Veröffentlicht 19.06.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:40:05
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitat...
CVE-2019-1989
- EPSS 1.67%
- Veröffentlicht 19.06.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:37:50
In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for e...
CVE-2019-1990
- EPSS 1.67%
- Veröffentlicht 19.06.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:37:50
In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for expl...
CVE-2019-2004
- EPSS 0.04%
- Veröffentlicht 19.06.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:02
In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVE-2019-2005
- EPSS 0.11%
- Veröffentlicht 19.06.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:03
In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. This could lead to local escalation of privilege on a locked device with no additional execution privil...
- EPSS 0.14%
- Veröffentlicht 19.06.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:03
In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not nee...
- EPSS 0.17%
- Veröffentlicht 19.06.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:03
In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User...