CVE-2019-2001
- EPSS 0.02%
- Veröffentlicht 28.02.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:40:02
The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android I...
CVE-2019-1986
- EPSS 0.34%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:49
In SkSwizzler::onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege in system_server with no additional execution privileges needed. User interaction ...
CVE-2019-1987
- EPSS 0.16%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:49
In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: A...
CVE-2019-1988
- EPSS 0.48%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:49
In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitat...
CVE-2019-1991
- EPSS 1.01%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:50
In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: And...
CVE-2019-1992
- EPSS 0.76%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:50
In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: ...
CVE-2019-1993
- EPSS 0.02%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:50
In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product...
CVE-2019-1994
- EPSS 0.14%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:50
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. Use...
CVE-2019-1995
- EPSS 0.02%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:50
In ComposeActivityEmail of ComposeActivityEmail.java, there is a possible way to silently attach files to an email due to a confused deputy. This could lead to local information disclosure, sending files accessible to AOSP Mail to a remote email reci...
CVE-2019-1996
- EPSS 0.16%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:50
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not ...