CVE-2019-2102
- EPSS 0.1%
- Veröffentlicht 07.06.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:14
In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK, it is theoretically possible for a proximate attacker to remotely inject keystrokes on a paired And...
CVE-2019-2090
- EPSS 0.01%
- Veröffentlicht 07.06.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:40:12
In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing permissions check. This could lead to local escalation of privilege, with no additional permissions required. User interaction is ...
- EPSS 0.87%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:07
In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploit...
CVE-2019-2049
- EPSS 0.02%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:08
In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional execution privileges needed. User...
CVE-2019-2050
- EPSS 0.01%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:08
In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVE-2019-2051
- EPSS 0.4%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:08
In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when processing a proxy auto config file with no additional execution privileges needed. User interaction i...
CVE-2019-2052
- EPSS 0.4%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:08
In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Andr...
CVE-2019-2053
- EPSS 0.02%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:08
In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVE-2019-2054
- EPSS 0.38%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:08
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User ...
CVE-2019-2043
- EPSS 0.01%
- Veröffentlicht 08.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:40:07
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with...