CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-9298

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112892194

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9299

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663886

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-9301

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663384

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9305

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661835

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9306

    Last Modified: 21 Nov 2024

    In libMpegTPDec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661348

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9240

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121150966

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9247

    Last Modified: 21 Nov 2024

    In AAC Codec, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120426166

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9262

    Last Modified: 21 Nov 2024

    In MPEG4Extractor, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111792351

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9237

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121325979

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9239

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121263487

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9246

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120428637

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9251

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120274615

    Published: 27 Sept 2019
    4.4
    Medium

    CVE-2019-9253

    Last Modified: 21 Nov 2024

    In KeyStore, there is a possible storage of symmetric keys in the TEE instead of the strongbox due to a missing strongbox flag. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109769728

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-9256

    Last Modified: 21 Nov 2024

    In libmediaextractor there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111921829

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9261

    Last Modified: 21 Nov 2024

    In libxaac there is a possible out of bounds read due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116774214

    Published: 27 Sept 2019
    7.3
    High

    CVE-2019-9269

    Last Modified: 21 Nov 2024

    In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-36899497

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9238

    Last Modified: 21 Nov 2024

    In the NFC stack, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121267042

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9241

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121036603

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9242

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-121035878

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9243

    Last Modified: 21 Nov 2024

    In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120905706

    Published: 27 Sept 2019
    5
    Medium

    CVE-2019-9244

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120865977

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9249

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9250

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120276962

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9252

    Last Modified: 21 Nov 2024

    In libavc there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73339042

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9257

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113572342

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9258

    Last Modified: 21 Nov 2024

    In wifilogd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113655028

    Published: 27 Sept 2019
    6.7
    Medium

    CVE-2019-9259

    Last Modified: 21 Nov 2024

    In the Bluetooth stack, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113575306

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9260

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113495295

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9263

    Last Modified: 21 Nov 2024

    In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73136824

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9264

    Last Modified: 21 Nov 2024

    In libxaac there is a possible out of bounds read due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116774502

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9265

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-37994606

    Published: 27 Sept 2019
    6.7
    Medium

    CVE-2019-9266

    Last Modified: 21 Nov 2024

    In sensorservice, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-119501435

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9268

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-77474014

    Published: 27 Sept 2019
    5.5
    Medium

    CVE-2019-9272

    Last Modified: 21 Nov 2024

    In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to determine device location with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-11596047

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2151

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117495174

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2158

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118766492

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2165

    Last Modified: 21 Nov 2024

    In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112712154

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2172

    Last Modified: 21 Nov 2024

    In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113035224

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9232

    Last Modified: 21 Nov 2024

    In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9233

    Last Modified: 21 Nov 2024

    In wpa_supplicant_8, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122529021

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-9234

    Last Modified: 21 Nov 2024

    In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122465453

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2150

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117935831

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2152

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118145923

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2155

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117655547

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2157

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112611363

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-2159

    Last Modified: 21 Nov 2024

    In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112707186

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2162

    Last Modified: 21 Nov 2024

    In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112713720

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2164

    Last Modified: 21 Nov 2024

    In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113263695

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2171

    Last Modified: 21 Nov 2024

    In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113035086

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-2153

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112611181

    Published: 27 Sept 2019