CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2018-9581

    Last Modified: 21 Nov 2024

    In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.STATE_CHANGE intents. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111698366

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9462

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-91544774

    Published: 27 Sept 2019
    3.3
    Low

    CVE-2019-9440

    Last Modified: 21 Nov 2024

    In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of the Email app's protected files with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-37637796

    Published: 27 Sept 2019
    —
    Unknown

    CVE-2019-9460

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. It was intended to be published earlier but will be made public later instead. Notes: none

    Published: 27 Sept 2019
    7.3
    High

    CVE-2019-9463

    Last Modified: 21 Nov 2024

    In Platform, there is a possible bypass of user interaction requirements due to background app interception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113584607

    Published: 27 Sept 2019
    7.8
    High

    CVE-2018-9425

    Last Modified: 21 Nov 2024

    In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73884967

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9404

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112923309

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9405

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112890225

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9411

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112204845

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9412

    Last Modified: 21 Nov 2024

    In libSBRdec there is a possible out of bounds read due to incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112006096

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9419

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111407544

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9432

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80546108

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9410

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112204443

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9418

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111450210

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9425

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110846194

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9406

    Last Modified: 21 Nov 2024

    In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112552517

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9407

    Last Modified: 21 Nov 2024

    In notification management of the service manager, there is a possible permissions bypass. This could lead to local escalation of privilege by preventing user notification, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112434609

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9408

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112380157

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9409

    Last Modified: 21 Nov 2024

    In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112272091

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9413

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111935831

    Published: 27 Sept 2019
    5.9
    Medium

    CVE-2019-9414

    Last Modified: 21 Nov 2024

    In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicConstraints field of intermediary certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111893041

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9415

    Last Modified: 21 Nov 2024

    In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111805098

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9416

    Last Modified: 21 Nov 2024

    In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111804142

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9417

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111450079

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9423

    Last Modified: 21 Nov 2024

    In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation. Product: AndroidVersions: Android-10Android ID: A-110986616

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9420

    Last Modified: 21 Nov 2024

    In libhevc, there is a possible out of bounds read due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111272481

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9421

    Last Modified: 21 Nov 2024

    In libandroidfw, there is a possible OOB read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111215250

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9422

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214766

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9424

    Last Modified: 21 Nov 2024

    In the Screen Lock, there is a possible information disclosure due to an unusual root cause. In certain circumstances, the setting to hide the unlock pattern can be ignored. Product: AndroidVersions: Android-10Android ID: A-110941092

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9427

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible information disclosure due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110166350

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9428

    Last Modified: 21 Nov 2024

    In the Framework, it is possible to set up BROWSEABLE intents to take over certain URLs. This could lead to remote information disclosure of sensitive URLs with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110150807

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9429

    Last Modified: 21 Nov 2024

    In profman, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110035108

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9430

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible null pointer dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109838296

    Published: 27 Sept 2019
    4.9
    Medium

    CVE-2019-9431

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109755179

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9433

    Last Modified: 21 Nov 2024

    In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354

    Published: 27 Sept 2019
    4.9
    Medium

    CVE-2019-9434

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80432895

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9435

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80146682

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9376

    Last Modified: 21 Nov 2024

    In Account of Account.java, there is a possible boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android; Versions: Android-9, Android-8.0, Android-8.1; Android ID: A-129287265.

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9383

    Last Modified: 21 Nov 2024

    In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120843827

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9385

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120452956

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9388

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117567437

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9389

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117567058

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9390

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117551475

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9395

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116267405

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9398

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115745406

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9402

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115372550

    Published: 27 Sept 2019
    —
    Unknown

    CVE-2019-9374

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 27 Sept 2019
    6.4
    Medium

    CVE-2019-9375

    Last Modified: 21 Nov 2024

    In hostapd, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-129344244

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9382

    Last Modified: 21 Nov 2024

    In libeffects, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120874654

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9391

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111050781

    Published: 27 Sept 2019