CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-9317

    Last Modified: 21 Nov 2024

    In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112052258

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9325

    Last Modified: 21 Nov 2024

    In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9332

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78286500

    Published: 27 Sept 2019
    7.3
    High

    CVE-2019-9309

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117985575

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9314

    Last Modified: 21 Nov 2024

    In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112329563

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9316

    Last Modified: 21 Nov 2024

    In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112052432

    Published: 27 Sept 2019
    5.3
    Medium

    CVE-2019-9323

    Last Modified: 21 Nov 2024

    In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-30770233

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9331

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112272279

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9308

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661742

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9312

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78288018

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9313

    Last Modified: 21 Nov 2024

    In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112005441

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9315

    Last Modified: 21 Nov 2024

    In libhevc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112326216

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9318

    Last Modified: 21 Nov 2024

    In libhevc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111764725

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9319

    Last Modified: 21 Nov 2024

    In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111762100

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9320

    Last Modified: 21 Nov 2024

    In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111761624

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9321

    Last Modified: 21 Nov 2024

    In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111208713

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9322

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111128067

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9326

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111215173

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9327

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112050583

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9328

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111895000

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9329

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112917952

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9330

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111214739

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9333

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109753657

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9334

    Last Modified: 21 Nov 2024

    In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112859934

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9283

    Last Modified: 4 Nov 2025

    In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663564

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9279

    Last Modified: 21 Nov 2024

    In the wifi hotspot service, there is a possible denial of service due to a null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-110476382

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9282

    Last Modified: 21 Nov 2024

    In skia, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113211371

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9286

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111213909

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9287

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78287084

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9290

    Last Modified: 21 Nov 2024

    In tzdata there is possible memory corruption due to a mismatch between allocation and deallocation functions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113039724

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9296

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112162089

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9300

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661610

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9303

    Last Modified: 21 Nov 2024

    In libFDK, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661057

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9304

    Last Modified: 21 Nov 2024

    In libMpegTPDec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112662270

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9278

    Last Modified: 21 Nov 2024

    In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9284

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111850706

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9289

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79883824

    Published: 27 Sept 2019
    3.3
    Low

    CVE-2019-9292

    Last Modified: 21 Nov 2024

    In the Activity Manager service, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of current foreground process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-115384617

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9295

    Last Modified: 21 Nov 2024

    In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-36885811

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9297

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112890242

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9302

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661356

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9307

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661893

    Published: 27 Sept 2019
    3.3
    Low

    CVE-2019-9277

    Last Modified: 21 Nov 2024

    In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-68016944

    Published: 27 Sept 2019
    3.3
    Low

    CVE-2019-9280

    Last Modified: 21 Nov 2024

    In keyguard, there is a possible escalation of privilege due to improper permission checks. This could lead to a local bypass of the keyguard under limited circumstances, with User execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-119322269

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9281

    Last Modified: 21 Nov 2024

    In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction requirements with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-32748076

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9285

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111215315

    Published: 27 Sept 2019
    6.8
    Medium

    CVE-2019-9288

    Last Modified: 21 Nov 2024

    In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android Versions: Android-10 Android ID: A-111363077

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9291

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible remote code execution due to an improper memory allocation. This could lead to remote code execution in Bluetooth with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112159179

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9293

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117661116

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9294

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111764444

    Published: 27 Sept 2019