CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-9397

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115747410

    Published: 27 Sept 2019
    5.9
    Medium

    CVE-2019-9399

    Last Modified: 21 Nov 2024

    The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115635664

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9371

    Last Modified: 21 Nov 2024

    In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9372

    Last Modified: 21 Nov 2024

    In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132782448

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9373

    Last Modified: 21 Nov 2024

    In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-130173029

    Published: 27 Sept 2019
    3.3
    Low

    CVE-2019-9377

    Last Modified: 21 Nov 2024

    In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biometrics of another user on the device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128599663

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9378

    Last Modified: 21 Nov 2024

    In the Activity Manager service, there is a possible permission bypass due to incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-124539196

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9379

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-124329638

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9380

    Last Modified: 21 Nov 2024

    In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permission settings with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-123700098

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9381

    Last Modified: 21 Nov 2024

    In netd, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122677612

    Published: 27 Sept 2019
    6.7
    Medium

    CVE-2019-9384

    Last Modified: 21 Nov 2024

    In LockPatternUtils, there is a possible escalation of privilege due to an improper permissions check. This could lead to local bypass of the Lockguard with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120568007

    Published: 27 Sept 2019
    7.3
    High

    CVE-2019-9386

    Last Modified: 21 Nov 2024

    In NFC server, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122361874

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9387

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117569833

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9393

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116357965

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9394

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116351796

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9396

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115747155

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9400

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible null pointer dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115509589

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9401

    Last Modified: 21 Nov 2024

    In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115375248

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9403

    Last Modified: 21 Nov 2024

    In cn-cbor, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113512324

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9341

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214770

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9343

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112050983

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9354

    Last Modified: 21 Nov 2024

    In NFC server, there's a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118148142

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9355

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115903122

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9361

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111762807

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9368

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79883568

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9347

    Last Modified: 21 Nov 2024

    In the m4v_h263 codec, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109891727

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9353

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-123024201

    Published: 27 Sept 2019
    7.3
    High

    CVE-2019-9358

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120156401

    Published: 27 Sept 2019
    4.4
    Medium

    CVE-2019-9360

    Last Modified: 21 Nov 2024

    In the TEE, there's a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120610663

    Published: 27 Sept 2019
    3.3
    Low

    CVE-2019-9364

    Last Modified: 21 Nov 2024

    In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to local information disclosure by playing the background user's audio with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73364631

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9367

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112106425

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9342

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214470

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9344

    Last Modified: 21 Nov 2024

    In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120845341

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9346

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128433933

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9348

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128431761

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9349

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-124330204

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9350

    Last Modified: 21 Nov 2024

    In Keymaster, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-129562815

    Published: 27 Sept 2019
    3.3
    Low

    CVE-2019-9351

    Last Modified: 21 Nov 2024

    In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128599864

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9352

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-124253062

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9356

    Last Modified: 21 Nov 2024

    In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111699773

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9357

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112662995

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9359

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111407302

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9362

    Last Modified: 21 Nov 2024

    In libSACdec, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120426980

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9363

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-123584306

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-9365

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109838537

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9366

    Last Modified: 21 Nov 2024

    In libSBRdec there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112052062

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9369

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79995407

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9370

    Last Modified: 21 Nov 2024

    In sonivox, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-133880046

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9310

    Last Modified: 21 Nov 2024

    In libFDK, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112891546

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9311

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible crash due to an integer overflow. This could lead to remote denial of service on incoming calls with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79431031

    Published: 27 Sept 2019