Google Security Advisories · August 2019 — Google Security Advisories
628 advisories 321 CVEs 8 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2019-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 8 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DEBIAN-CVE-2019-11248

Open SourceExploitedCISA KEV listedHIGH2019-08-29

DEBIAN-CVE-2019-11248

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2019-11248

Open SourceExploitedCISA KEV listedHIGH2019-08-29

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet ...

CVEs:CVE-2019-11248

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2019-11248

GoogleExploitedCISA KEV listed2019-08-29

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

CVEs:CVE-2019-11248

Upstream advisory

DSA-4500-1

Open SourceExploitedCISA KEV listed2019-08-12

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

openSUSE-SU-2019:2021-1

Open SourceExploitedVulnCheck KEV listedHIGH2019-08-29

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected openSUSE:Leap 15.1 containerd
containerd affected openSUSE:Leap 15.0 containerd
docker affected openSUSE:Leap 15.1 docker
docker affected openSUSE:Leap 15.0 docker
docker-runc affected openSUSE:Leap 15.0 docker-runc
docker-runc affected openSUSE:Leap 15.1 docker-runc
golang-github-docker-libnetwork affected openSUSE:Leap 15.1 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected openSUSE:Leap 15.0 golang-github-docker-libnetwork
Upstream advisory

SUSE-SU-2019:2119-1

Open SourceExploitedVulnCheck KEV listedHIGH2019-08-13

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:OpenStack Cloud 6-LTSS containerd
containerd affected SUSE:Linux Enterprise Module for Containers 12 containerd
docker affected SUSE:Linux Enterprise Module for Containers 12 docker
docker affected SUSE:OpenStack Cloud 6-LTSS docker
docker-runc affected SUSE:OpenStack Cloud 6-LTSS docker-runc
docker-runc affected SUSE:Linux Enterprise Module for Containers 12 docker-runc
golang-github-docker-libnetwork affected SUSE:OpenStack Cloud 6-LTSS golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 12 golang-github-docker-libnetwork
Upstream advisory

SUSE-SU-2019:2117-1

Open SourceExploitedVulnCheck KEV listedHIGH2019-08-13

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 15 containerd
containerd affected SUSE:Linux Enterprise Module for Containers 15 SP1 containerd
docker affected SUSE:Linux Enterprise Module for Containers 15 SP1 docker
docker affected SUSE:Linux Enterprise Module for Containers 15 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 docker-runc
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 SP1 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 SP1 golang-github-docker-libnetwork
Upstream advisory

CVE-2017-18487

GoogleWeaponized exploitCRITICAL2019-08-13

The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.

CVEs:CVE-2017-18487

Affected products

ProductStatusVendorPackageEcosystem
google_adsense affected google_adsense_project
Upstream advisory

CVE-2017-18557

GoogleWeaponized exploitCRITICAL2019-08-21

The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.

CVEs:CVE-2017-18557

Affected products

ProductStatusVendorPackageEcosystem
google_maps affected bestwebsoft
Upstream advisory

CVE-2017-18556

GoogleWeaponized exploitCRITICAL2019-08-21

The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.

CVEs:CVE-2017-18556

Affected products

ProductStatusVendorPackageEcosystem
google_analytics affected bestwebsoft
Upstream advisory

DSA-4503-1

Open SourcePoC exploit2019-08-18

golang-1.11 - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-1.11 affected Debian:10 golang-1.11
Upstream advisory

CVE-2019-9512

Open SourcePoC exploitHIGH2019-08-13

golang.org/x/net/http vulnerable to ping floods

CVEs:CVE-2019-9512

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2019-9512

GooglePoC exploitHIGH2019-08-13

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this dat...

CVEs:CVE-2019-9512

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
node.js affected nodejs
swiftnio affected apple
traffic_server affected apache
Upstream advisory

CVE-2019-9512

Open SourcePoC exploitHIGH2019-08-13

golang.org/x/net/http vulnerable to a reset flood

CVEs:CVE-2019-9512

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2019-9514

GooglePoC exploitHIGH2019-08-13

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the pee...

CVEs:CVE-2019-9514

Affected products

ProductStatusVendorPackageEcosystem
big-ip_local_traffic_manager affected f5
cloud_insights affected netapp
debian_linux affected debian
developer_tools affected redhat
diskstation_manager affected synology
enterprise_linux affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
graalvm affected oracle
jboss_core_services affected redhat
jboss_enterprise_application_platform affected redhat
leap affected opensuse
node.js affected nodejs
openshift_container_platform affected redhat
openshift_service_mesh affected redhat
openstack affected redhat
quay affected redhat
single_sign-on affected redhat
skynas affected synology
software_collections affected redhat
swiftnio affected apple
traffic_server affected apache
trident affected netapp
ubuntu_linux affected canonical
vs960hd_firmware affected synology
web_gateway affected mcafee
Upstream advisory

CVE-2019-9514

Open SourcePoC exploitHIGH2019-08-13

golang.org/x/net/http vulnerable to a reset flood

CVEs:CVE-2019-9514

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2019-11249

Open SourcePoC exploitMEDIUM2019-08-29

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s ma...

CVEs:CVE-2019-11249

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

CVE-2019-11246

Open SourcePoC exploitMEDIUM2019-08-29

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s ma...

CVEs:CVE-2019-11246

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2019-9506

Open SourcePoC exploitHIGH2019-08-13

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that ...

CVEs:CVE-2019-9506

Affected products

ProductStatusVendorPackageEcosystem
alp-al00b_firmware affected huawei
android affected google
ares-al00b_firmware affected huawei
ares-al10d_firmware affected huawei
ares-tl00c_firmware affected huawei
asoka-al00ax_firmware affected huawei
atomu-l33_firmware affected huawei
atomu-l41_firmware affected huawei
atomu-l42_firmware affected huawei
barca-al00_firmware affected huawei
berkeley-al20_firmware affected huawei
berkeley-l09_firmware affected huawei
berkeley-tl10_firmware affected huawei
bla-al00b_firmware affected huawei
bla-l29c_firmware affected huawei
bla-tl00b_firmware affected huawei
cairogo-l22_firmware affected huawei
charlotte-l29c_firmware affected huawei
columbia-al10b_firmware affected huawei
columbia-al10i_firmware affected huawei
columbia-l29d_firmware affected huawei
columbia-tl00d_firmware affected huawei
cornell-al00a_firmware affected huawei
cornell-al00i_firmware affected huawei
cornell-al00ind_firmware affected huawei
cornell-al10ind_firmware affected huawei
cornell-l29a_firmware affected huawei
cornell-tl10b_firmware affected huawei
debian_linux affected debian
dubai-al00a_firmware affected huawei
dura-al00a_firmware affected huawei
dura-tl00a_firmware affected huawei
emily-l29c_firmware affected huawei
enterprise_linux affected redhat
enterprise_linux_aus affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_for_real_time affected redhat
enterprise_linux_for_real_time_eus affected redhat
enterprise_linux_for_real_time_for_nfv affected redhat
enterprise_linux_for_real_time_for_nfv_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_aus affected redhat
enterprise_linux_server_tus affected redhat
enterprise_linux_tus affected redhat
ever-l29b_firmware affected huawei
figo-l23_firmware affected huawei
figo-l31_firmware affected huawei
figo-tl10b_firmware affected huawei
florida-al20b_firmware affected huawei
florida-l21_firmware affected huawei
florida-l22_firmware affected huawei
florida-l23_firmware affected huawei
florida-tl10b_firmware affected huawei
harry-al00c_firmware affected huawei
harry-al10b_firmware affected huawei
harry-tl00c_firmware affected huawei
hima-l29c_firmware affected huawei
honor_10_lite_firmware affected huawei
honor_20_firmware affected huawei
honor_20_pro_firmware affected huawei
honor_8a_firmware affected huawei
honor_8x_firmware affected huawei
honor_view_10_firmware affected huawei
honor_view_20_firmware affected huawei
imanager_neteco_6000_firmware affected huawei
imanager_neteco_firmware affected huawei
iphone_os affected apple
jakarta-al00a_firmware affected huawei
johnson-tl00d_firmware affected huawei
johnson-tl00f_firmware affected huawei
katyusha-al00a_firmware affected huawei
laya-al00ep_firmware affected huawei
leap affected opensuse
leland-l21a_firmware affected huawei
leland-l31a_firmware affected huawei
leland-l32a_firmware affected huawei
leland-l32c_firmware affected huawei
leland-l42a_firmware affected huawei
leland-l42c_firmware affected huawei
lelandp-al00c_firmware affected huawei
lelandp-al10b_firmware affected huawei
lelandp-al10d_firmware affected huawei
lelandp-l22a_firmware affected huawei
lelandp-l22c_firmware affected huawei
lelandp-l22d_firmware affected huawei
leland-tl10b_firmware affected huawei
leland-tl10c_firmware affected huawei
london-al40ind_firmware affected huawei
mac_os_x affected apple
madrid-al00a_firmware affected huawei
madrid-tl00a_firmware affected huawei
mate_20_firmware affected huawei
mate_20_pro_firmware affected huawei
mate_20_x_firmware affected huawei
mrg_realtime affected redhat
neo-al00d_firmware affected huawei
nova_3_firmware affected huawei
nova_4_firmware affected huawei
nova_5_firmware affected huawei
nova_5i_pro_firmware affected huawei
nova_lite_3_firmware affected huawei
p20_firmware affected huawei
p20_pro_firmware affected huawei
p30_firmware affected huawei
p30_pro_firmware affected huawei
paris-al00ic_firmware affected huawei
paris-l21b_firmware affected huawei
paris-l21meb_firmware affected huawei
paris-l29b_firmware affected huawei
potter-al00c_firmware affected huawei
potter-al10a_firmware affected huawei
princeton-al10b_firmware affected huawei
princeton-al10d_firmware affected huawei
princeton-tl10c_firmware affected huawei
p_smart_2019_firmware affected huawei
p_smart_firmware affected huawei
sydney-al00_firmware affected huawei
sydney-l21br_firmware affected huawei
sydney-l21_firmware affected huawei
sydney-l22br_firmware affected huawei
sydney-l22_firmware affected huawei
sydneym-al00_firmware affected huawei
sydneym-l01_firmware affected huawei
sydneym-l03_firmware affected huawei
sydneym-l21_firmware affected huawei
sydneym-l22_firmware affected huawei
sydneym-l23_firmware affected huawei
sydney-tl00_firmware affected huawei
tony-al00b_firmware affected huawei
tony-tl00b_firmware affected huawei
tvos affected apple
ubuntu_linux affected canonical
virtualization_host_eus affected redhat
watchos affected apple
y5_2018_firmware affected huawei
y5_lite_firmware affected huawei
y6_2019_firmware affected huawei
y6_prime_2018_firmware affected huawei
y6_pro_2019_firmware affected huawei
y7_2019_firmware affected huawei
y9_2019_firmware affected huawei
yale-al00a_firmware affected huawei
yale-al50a_firmware affected huawei
yale-l21a_firmware affected huawei
yale-l61c_firmware affected huawei
yalep-al10b_firmware affected huawei
yale-tl00b_firmware affected huawei
Upstream advisory

DEBIAN-CVE-2019-11247

Open SourcePoC exploitCRITICAL2019-08-29

DEBIAN-CVE-2019-11247

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2019-11247

Open SourcePoC exploitHIGH2019-08-29

Kubernetes kube-apiserver unauthorized access

CVEs:CVE-2019-11247

Affected products

ProductStatusVendorPackageEcosystem
apiextensions-apiserver affected k8s.io k8s.io/apiextensions-apiserver
Upstream advisory

CVE-2019-11247

Open SourcePoC exploitCRITICAL2019-08-29

The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings wit...

CVEs:CVE-2019-11247

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

DEBIAN-CVE-2019-11250

Open SourcePoC exploitMEDIUM2019-08-29

DEBIAN-CVE-2019-11250

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:14 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
Upstream advisory

CVE-2019-11250

Open SourcePoC exploitMEDIUM2019-08-29

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of...

CVEs:CVE-2019-11250

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift_container_platform affected redhat
Upstream advisory

CVE-2019-11250

Open SourcePoC exploitMEDIUM2019-08-29

Kubernetes client-go library logs may disclose credentials to unauthorized users

CVEs:CVE-2019-11250

Affected products

ProductStatusVendorPackageEcosystem
client-go affected k8s.io k8s.io/client-go
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2019-11245

Open SourcePoC exploitHIGH2019-08-29

In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubel...

CVEs:CVE-2019-11245

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2019-11245

Open SourcePoC exploitMEDIUM2019-08-29

Kubelet Incorrect Privilege Assignment

CVEs:CVE-2019-11245

Affected products

ProductStatusVendorPackageEcosystem
kubernetes/cmd/kubelet affected k8s.io k8s.io/kubernetes/cmd/kubelet
Upstream advisory

CVE-2019-9376

Open SourcePoC exploitMEDIUM2019-08-21

In Account of Account.java, there is a possible boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android; Ver...

CVEs:CVE-2019-9376

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2019:1901-1

Open SourceCoalition ESS 30-63%HIGH2019-08-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2019:1853-1

Open SourceCoalition ESS 30-63%HIGH2019-08-13

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 chromium
Upstream advisory

openSUSE-SU-2019:1849-1

Open SourceCoalition ESS 30-63%HIGH2019-08-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

openSUSE-SU-2019:1848-1

Open SourceCoalition ESS 30-63%HIGH2019-08-12

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.0 chromium
Upstream advisory

openSUSE-SU-2019:1931-1

Open SourceCoalition ESS 30-63%CRITICAL2019-08-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 chromium
Upstream advisory

openSUSE-SU-2019:1928-1

Open SourceCoalition ESS 30-63%CRITICAL2019-08-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2019:1903-1

Open SourceCoalition ESS 30-63%CRITICAL2019-08-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.0 chromium
Upstream advisory

openSUSE-SU-2019:1902-1

Open SourceCoalition ESS 30-63%CRITICAL2019-08-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2019-5868

GoogleCoalition ESS 30-63%CRITICAL2019-08-07

Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2019-5868

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

AZL-78948

Open SourceCoalition ESS < 30%CRITICAL2019-08-13

CVE-2019-14809 affecting package golang 1.25.7-1

Affected products

ProductStatusVendorPackageEcosystem
golang affected Azure Linux:3 golang
Upstream advisory

CVE-2019-14809

GoogleCoalition ESS < 30%CRITICAL2019-08-13

net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related ...

CVEs:CVE-2019-14809

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
go affected golang
Upstream advisory

CVE-2019-2126

Open SourceCoalition ESS < 30%HIGH2019-08-06

In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitatio...

CVEs:CVE-2019-2126

Affected products

ProductStatusVendorPackageEcosystem
android affected google
fedora affected fedoraproject
leap affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-9232

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9232

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-9278

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation....

CVEs:CVE-2019-9278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-9371

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9371

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-9433

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9433

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-9325

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9325

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
leap affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2019-14993

Open SourceCoalition ESS < 30%HIGH2019-08-13

Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding API.

CVEs:CVE-2019-14993

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2019-3800

GoogleCoalition ESS < 30%HIGH2019-08-05

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can ...

CVEs:CVE-2019-3800

Affected products

ProductStatusVendorPackageEcosystem
application_analytics affected appdynamics
application_monitoring affected datadoghq
application_performance_monitoring affected appdynamics
application_service affected pivotal
azure_log_analytics_nozzle affected microsoft
azure_service_broker affected microsoft
businessworks_buildpack affected tibco
cloud_foundry_autoscaling_release affected pivotal
cloud_foundry_command_line_interface affected pivotal
cloud_foundry_command_line_interface_release affected pivotal
cloud_foundry_deployment affected pivotal
cloud_foundry_deployment_concourse_tasks affected pivotal
cloud_foundry_event_alerts affected pivotal
cloud_foundry_healthwatch affected pivotal
cloud_foundry_log_cache_release affected pivotal
cloud_foundry_networking_release affected pivotal
cloud_foundry_notifications affected pivotal
cloud_foundry_routing_release affected pivotal
cloud_foundry_smoke_test affected pivotal
conjur_service_broker affected cyberark
credhub_service_broker_for_pcf affected pivotal
db_enterprise affected yugabyte
dotnet_extension_buildpack affected newrelic
edge_service_broker affected apigee
elasticsearch affected anynines
enterprise_service_broker affected datastax
google_cloud_platform_service_broker affected google
logme affected anynines
metric_registrar_release affected pivotal
mongodb affected anynines
mysql affected anynines
nozzle affected bluemedora
nozzle affected splunk
nozzle affected sumologic
nozzle affected newrelic
on_demand_service_broker affected pivotal
pivotal_cloud_foundry_service_broker affected pivotal
platform_montioring affected appdynamics
postgresql affected anynines
pubsub\+ affected solace
rabbitmq affected anynines
redis affected anynines
seeker_iast_service_broker affected synopsys
service_broker affected forgerock
service_broker affected snyk
service_broker affected newrelic
service_broker affected dynatrace
service_broker affected contrastsecurity
service_broker affected pagerduty
service_broker affected signalsciences
single_sign-on affected pivotal
steelcentral_appinternals affected riverbed
volume_service affected samba
wavefront_by_vmware_nozzle affected wavefront
websphere_liberty_ affected ibm
Upstream advisory

CVE-2019-2130

Open SourceCoalition ESS < 30%HIGH2019-08-06

In CompilationJob::FinalizeJob of compiler.cc, there is a possible remote code execution due to type confusion. This could lead to escalation of privilege from a malicious proxy configuration with no additional execution privileges needed. User interac...

CVEs:CVE-2019-2130

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9459

Open SourceCoalition ESS < 30%CRITICAL2019-08-21

In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9279

Open SourceCoalition ESS < 30%HIGH2019-08-21

In the wifi hotspot service, there is a possible denial of service due to a null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: ...

CVEs:CVE-2019-9279

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9400

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible null pointer dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9400

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9430

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible null pointer dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9365

Open SourceCoalition ESS < 30%CRITICAL2019-08-21

In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions...

CVEs:CVE-2019-9365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9283

Open SourceCoalition ESS < 30%HIGH2019-08-21

In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: A...

CVEs:CVE-2019-9283

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9428

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In the Framework, it is possible to set up BROWSEABLE intents to take over certain URLs. This could lead to remote information disclosure of sensitive URLs with no additional execution privileges needed. User interaction is needed for exploitation. Pro...

CVEs:CVE-2019-9428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-11516

Open SourceCoalition ESS < 30%HIGH2019-08-06

An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Extended Inquiry Responses (EIRs) are improperly handled, which causes a heap-based buffer overflow during device inquiry. This overfl...

CVEs:CVE-2019-11516

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2062

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9301

Open SourceCoalition ESS < 30%CRITICAL2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9367

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9367

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9256

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libmediaextractor there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9256

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9262

Open SourceCoalition ESS < 30%HIGH2019-08-21

In MPEG4Extractor, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation. Product:...

CVEs:CVE-2019-9262

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9233

Open SourceCoalition ESS < 30%HIGH2019-08-21

In wpa_supplicant_8, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: And...

CVEs:CVE-2019-9233

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9234

Open SourceCoalition ESS < 30%HIGH2019-08-21

In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Androi...

CVEs:CVE-2019-9234

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9241

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9241

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9250

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9250

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9260

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVer...

CVEs:CVE-2019-9260

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9265

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVer...

CVEs:CVE-2019-9265

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9286

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9286

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9326

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9326

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9327

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9327

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9330

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9330

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9331

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9331

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9332

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9332

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9341

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9341

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9342

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9343

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9355

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9355

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9381

Open SourceCoalition ESS < 30%HIGH2019-08-21

In netd, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9381

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9387

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9387

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9388

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2019-9388

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9413

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9413

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9419

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9422

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9422

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9432

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2019-9432

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9285

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: A...

CVEs:CVE-2019-9285

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9311

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible crash due to an integer overflow. This could lead to remote denial of service on incoming calls with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9311

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9389

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: A...

CVEs:CVE-2019-9389

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9390

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: A...

CVEs:CVE-2019-9390

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9393

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9393

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9394

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9394

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9395

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9395

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9396

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9396

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9397

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9397

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9398

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9398

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9401

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9401

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9402

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9402

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9404

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is possible controlled termination due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9404

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9425

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: A...

CVEs:CVE-2019-9425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5040

GoogleCoalition ESS < 30%CRITICAL2019-08-19

An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in P...

CVEs:CVE-2019-5040

Affected products

ProductStatusVendorPackageEcosystem
nest_cam_iq_indoor_firmware affected google
openweave-core affected openweave
Upstream advisory

CVE-2019-9335

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9335

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9336

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9336

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9337

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9337

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9338

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9338

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5869

GoogleCoalition ESS < 30%CRITICAL2019-08-27

Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5869

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-9281

Open SourceCoalition ESS < 30%HIGH2019-08-21

In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction requirements with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2019-9281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9346

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libstagefright, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: An...

CVEs:CVE-2019-9346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9333

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9333

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2129

Open SourceCoalition ESS < 30%MEDIUM2019-08-06

In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed ...

CVEs:CVE-2019-2129

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2162

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-2162

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9237

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9237

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9247

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In AAC Codec, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-12...

CVEs:CVE-2019-9247

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9252

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-...

CVEs:CVE-2019-9252

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9282

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In skia, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andro...

CVEs:CVE-2019-9282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9293

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libstagefright, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersi...

CVEs:CVE-2019-9293

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9294

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libstagefright, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersi...

CVEs:CVE-2019-9294

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9313

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:...

CVEs:CVE-2019-9313

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9314

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-11232...

CVEs:CVE-2019-9314

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9315

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libhevc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-1123...

CVEs:CVE-2019-9315

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9316

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:...

CVEs:CVE-2019-9316

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9317

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:...

CVEs:CVE-2019-9317

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9318

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libhevc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-1117...

CVEs:CVE-2019-9318

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9319

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-11176...

CVEs:CVE-2019-9319

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9320

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-11176...

CVEs:CVE-2019-9320

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9321

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-11120...

CVEs:CVE-2019-9321

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9322

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9334

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9334

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9353

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9353

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9359

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9359

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9361

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9361

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9362

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libSACdec, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9362

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9366

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libSBRdec there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: A...

CVEs:CVE-2019-9366

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9370

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In sonivox, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9370

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9385

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: An...

CVEs:CVE-2019-9385

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9403

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In cn-cbor, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-...

CVEs:CVE-2019-9403

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9406

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9406

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9408

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9408

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9409

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9409

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9410

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9410

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9411

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Andr...

CVEs:CVE-2019-9411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9412

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libSBRdec there is a possible out of bounds read due to incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: A...

CVEs:CVE-2019-9412

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9415

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9416

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9416

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2055

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2059

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2061

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2061

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2063

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Androi...

CVEs:CVE-2019-2063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2064

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2064

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2065

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2065

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2066

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2067

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2068

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2069

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2070

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2070

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2071

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2071

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2072

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2073

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Androi...

CVEs:CVE-2019-2073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2074

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2074

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2075

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2075

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2076

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2076

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2077

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2077

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2078

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2078

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2080

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2081

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2081

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2082

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2082

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2083

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2083

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2084

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2084

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2085

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2085

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2086

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2086

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2087

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2087

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2141

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2141

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2159

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2159

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9291

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible remote code execution due to an improper memory allocation. This could lead to remote code execution in Bluetooth with no additional execution privileges needed. User interaction is needed for exploitation. Product: An...

CVEs:CVE-2019-9291

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9297

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9297

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9298

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9299

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9299

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9300

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9300

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9302

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9302

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9303

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libFDK, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10And...

CVEs:CVE-2019-9303

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9304

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libMpegTPDec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9304

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9305

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9305

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9306

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libMpegTPDec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9306

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9307

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9307

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9308

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9308

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9310

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libFDK, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10And...

CVEs:CVE-2019-9310

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9357

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9357

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9363

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9363

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9382

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libeffects, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Androi...

CVEs:CVE-2019-9382

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9405

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9405

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5867

GoogleCoalition ESS < 30%MEDIUM2019-08-07

Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2019-5867

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2019-9431

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2019-9431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9434

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with heap information written to the log with System execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2019-9434

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9348

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9348

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9349

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9349

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9372

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: ...

CVEs:CVE-2019-9372

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9379

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9379

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9418

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9418

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5043

GoogleCoalition ESS < 30%CRITICAL2019-08-19

An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service. An attacker can connect multipl...

CVEs:CVE-2019-5043

Affected products

ProductStatusVendorPackageEcosystem
nest_cam_iq_indoor_firmware affected google
Upstream advisory

CVE-2019-9354

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC server, there's a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9354

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2148

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2148

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9352

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9352

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9420

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libhevc, there is a possible out of bounds read due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9420

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5034

GoogleCoalition ESS < 30%HIGH2019-08-19

An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. A...

CVEs:CVE-2019-5034

Affected products

ProductStatusVendorPackageEcosystem
nest_cam_iq_indoor_firmware affected google
Upstream advisory

CVE-2019-2060

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2079

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2138

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2138

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2139

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2139

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2140

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2140

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2142

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2142

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2143

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2143

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2144

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2144

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2145

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2145

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2146

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2146

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2147

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2147

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2149

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2149

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2150

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2150

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2151

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2151

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2152

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2152

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2153

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2153

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2154

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2154

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2155

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2155

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2156

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2156

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2157

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2157

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2158

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-1...

CVEs:CVE-2019-2158

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2160

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2160

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2161

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2161

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2163

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2163

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2164

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2164

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2165

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2165

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2166

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2166

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2167

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2167

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2168

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2168

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2169

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2169

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2170

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2170

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2171

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2171

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2172

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-2172

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9261

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10An...

CVEs:CVE-2019-9261

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9264

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac there is a possible out of bounds read due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10An...

CVEs:CVE-2019-9264

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9391

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In libxaac, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10And...

CVEs:CVE-2019-9391

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5037

GoogleCoalition ESS < 30%CRITICAL2019-08-19

An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped mem...

CVEs:CVE-2019-5037

Affected products

ProductStatusVendorPackageEcosystem
nest_cam_iq_indoor_firmware affected google
Upstream advisory

CVE-2019-9414

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In wpa_supplicant, there is a possible man in the middle vulnerability due to improper input validation of the basicConstraints field of intermediary certificates. This could lead to remote information disclosure with no additional execution privileges...

CVEs:CVE-2019-9414

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2133

Open SourceCoalition ESS < 30%HIGH2019-08-06

In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploi...

CVEs:CVE-2019-2133

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9284

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9284

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9328

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: And...

CVEs:CVE-2019-9328

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9329

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9329

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2131

Open SourceCoalition ESS < 30%HIGH2019-08-06

An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions:...

CVEs:CVE-2019-2131

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2132

Open SourceCoalition ESS < 30%HIGH2019-08-06

It is possible to overlay the VPN dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 A...

CVEs:CVE-2019-2132

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2134

Open SourceCoalition ESS < 30%HIGH2019-08-06

In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2019-2134

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2135

Open SourceCoalition ESS < 30%HIGH2019-08-06

In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2019-2135

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5036

GoogleCoalition ESS < 30%HIGH2019-08-19

An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial...

CVEs:CVE-2019-5036

Affected products

ProductStatusVendorPackageEcosystem
nest_cam_iq_indoor_firmware affected google
Upstream advisory

CVE-2019-9323

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction is not needed for exploitation. ...

CVEs:CVE-2019-9323

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9380

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permission settings with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2019-9380

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9399

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

The Print Service is susceptible to man in the middle attacks due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Andr...

CVEs:CVE-2019-9399

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-5035

GoogleCoalition ESS < 30%CRITICAL2019-08-19

An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access an...

CVEs:CVE-2019-5035

Affected products

ProductStatusVendorPackageEcosystem
nest_cam_iq_indoor_firmware affected google
Upstream advisory

CVE-2019-9424

Open SourceCoalition ESS < 30%HIGH2019-08-21

In the Screen Lock, there is a possible information disclosure due to an unusual root cause. In certain circumstances, the setting to hide the unlock pattern can be ignored. Product: AndroidVersions: Android-10Android ID: A-110941092

CVEs:CVE-2019-9424

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-10379

GoogleCoalition ESS < 30%MEDIUM2019-08-07

Jenkins Google Cloud Messaging Notification Plugin stores credentials in plain text

CVEs:CVE-2019-10379

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:gcm-notification affected Maven org.jenkins-ci.plugins:gcm-notification
Upstream advisory

CVE-2019-10379

GoogleCoalition ESS < 30%MEDIUM2019-08-07

Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

CVEs:CVE-2019-10379

Affected products

ProductStatusVendorPackageEcosystem
cloud_messaging_notification affected google
Upstream advisory

CVE-2019-9423

GoogleCoalition ESS < 30%HIGH2019-08-21

Out-of-bounds Write in OpenCV

CVEs:CVE-2019-9423

Affected products

ProductStatusVendorPackageEcosystem
opencv-contrib-python affected PyPI opencv-contrib-python
opencv-contrib-python-headless affected PyPI opencv-contrib-python-headless
opencv-python affected PyPI opencv-python
opencv-python-headless affected PyPI opencv-python-headless
Upstream advisory

CVE-2019-9423

Open SourceCoalition ESS < 30%HIGH2019-08-21

In opencv calls that use libpng, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges required. User interaction is not required for exploitation...

CVEs:CVE-2019-9423

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9423

GoogleCoalition ESS < 30%HIGH2019-08-21

Out-of-bounds Write in OpenCV

CVEs:CVE-2019-9423

Affected products

ProductStatusVendorPackageEcosystem
opencv-contrib-python affected PyPI opencv-contrib-python
opencv-contrib-python-headless affected PyPI opencv-contrib-python-headless
opencv-python affected PyPI opencv-python
opencv-python-headless affected PyPI opencv-python-headless
Upstream advisory

CVE-2019-14783

Open SourceCoalition ESS < 30%MEDIUM2019-08-08

On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create privileged files. The Samsung ID is SVE-2019-14764.

CVEs:CVE-2019-14783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9373

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute. This could lead to a local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Prod...

CVEs:CVE-2019-9373

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9358

Open SourceCoalition ESS < 30%HIGH2019-08-21

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9358

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9386

Open SourceCoalition ESS < 30%HIGH2019-08-21

In NFC server, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is needed for exploitation. Pro...

CVEs:CVE-2019-9386

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2128

Open SourceCoalition ESS < 30%HIGH2019-08-06

In ACELP_4t64_fx of c4t64fx.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Prod...

CVEs:CVE-2019-2128

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9238

Open SourceCoalition ESS < 30%HIGH2019-08-21

In the NFC stack, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: An...

CVEs:CVE-2019-9238

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2122

Open SourceCoalition ESS < 30%HIGH2019-08-06

In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the default case between the WindowManager and the Settings. This could lead to a local escalation of privilege with no additional exec...

CVEs:CVE-2019-2122

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9384

Open SourceCoalition ESS < 30%HIGH2019-08-21

In LockPatternUtils, there is a possible escalation of privilege due to an improper permissions check. This could lead to local bypass of the Lockguard with System execution privileges needed. User interaction is not needed for exploitation. Product: A...

CVEs:CVE-2019-9384

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9309

Open SourceCoalition ESS < 30%HIGH2019-08-21

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to a to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9309

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9277

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to local disclosure of app and browser activity with User execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2019-9277

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2136

Open SourceCoalition ESS < 30%HIGH2019-08-06

In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2019-2136

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2120

Open SourceCoalition ESS < 30%HIGH2019-08-06

In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

CVEs:CVE-2019-2120

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9239

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9239

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2127

Open SourceCoalition ESS < 30%HIGH2019-08-06

In AudioInputDescriptor::setClientActive of AudioInputDescriptor.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2019-2127

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9259

Open SourceCoalition ESS < 30%HIGH2019-08-21

In the Bluetooth stack, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions...

CVEs:CVE-2019-9259

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9266

Open SourceCoalition ESS < 30%HIGH2019-08-21

In sensorservice, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions...

CVEs:CVE-2019-9266

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9288

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2019-9288

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9290

Open SourceCoalition ESS < 30%HIGH2019-08-21

In tzdata there is possible memory corruption due to a mismatch between allocation and deallocation functions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2019-9290

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9429

Open SourceCoalition ESS < 30%HIGH2019-08-21

In profman, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: An...

CVEs:CVE-2019-9429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9235

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9235

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9236

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9236

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9240

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9240

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9242

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9242

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9244

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9244

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9246

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9246

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9251

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9251

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9296

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9296

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9344

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9356

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9356

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9407

Open SourceCoalition ESS < 30%HIGH2019-08-21

In notification management of the service manager, there is a possible permissions bypass. This could lead to local escalation of privilege by preventing user notification, with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2019-9407

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9243

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In wpa_supplicant_8, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android...

CVEs:CVE-2019-9243

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9257

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions...

CVEs:CVE-2019-9257

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9258

Open SourceCoalition ESS < 30%HIGH2019-08-21

In wifilogd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersio...

CVEs:CVE-2019-9258

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9350

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Keymaster, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android...

CVEs:CVE-2019-9350

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2137

Open SourceCoalition ESS < 30%MEDIUM2019-08-06

In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local denial of access to Emergency Services with User execution privileges needed. User interaction is not ne...

CVEs:CVE-2019-2137

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9269

Open SourceCoalition ESS < 30%HIGH2019-08-21

In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9269

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9253

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In KeyStore, there is a possible storage of symmetric keys in the TEE instead of the strongbox due to a missing strongbox flag. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2019-9253

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9360

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In the TEE, there's a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android...

CVEs:CVE-2019-9360

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9280

Open SourceCoalition ESS < 30%LOW2019-08-21

In keyguard, there is a possible escalation of privilege due to improper permission checks. This could lead to a local bypass of the keyguard under limited circumstances, with User execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2019-9280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9364

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to local information disclosure by playing the background user's audio with no additional execution privileges needed. User interaction i...

CVEs:CVE-2019-9364

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9295

Open SourceCoalition ESS < 30%HIGH2019-08-21

In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User interaction is needed for exploita...

CVEs:CVE-2019-9295

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9425

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Platform, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2018-9425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9263

Open SourceCoalition ESS < 30%HIGH2019-08-21

In telephony, there is a possible bypass of user interaction requirements due to missing permission checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2019-9263

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9378

Open SourceCoalition ESS < 30%HIGH2019-08-21

In the Activity Manager service, there is a possible permission bypass due to incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. ...

CVEs:CVE-2019-9378

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9383

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: ...

CVEs:CVE-2019-9383

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9421

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libandroidfw, there is a possible OOB read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10A...

CVEs:CVE-2019-9421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9249

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9249

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9287

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9287

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9289

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9289

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9312

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9312

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9347

Open SourceCoalition ESS < 30%HIGH2019-08-21

In the m4v_h263 codec, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVers...

CVEs:CVE-2019-9347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9368

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9368

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9369

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-7...

CVEs:CVE-2019-9369

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9417

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9417

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9427

Open SourceCoalition ESS < 30%HIGH2019-08-21

In Bluetooth, there is a possible information disclosure due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions:...

CVEs:CVE-2019-9427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9435

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...

CVEs:CVE-2019-9435

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9292

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In the Activity Manager service, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of current foreground process with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2019-9292

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9351

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure with no additional execution privil...

CVEs:CVE-2019-9351

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9438

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In the Package Manager service, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of information about installed packages for other users with no additional execution privileges needed. User intera...

CVEs:CVE-2019-9438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9440

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of the Email app's protected files with User execution privileges needed. User interaction is needed for exploitation. Product: Andr...

CVEs:CVE-2019-9440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2125

Open SourceCoalition ESS < 30%HIGH2019-08-06

In ChangeDefaultDialerDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privil...

CVEs:CVE-2019-2125

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9272

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to determine device location with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2019-9272

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9377

Open SourceCoalition ESS < 30%MEDIUM2019-08-21

In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biometrics of anoth...

CVEs:CVE-2019-9377

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2121

Open SourceCoalition ESS < 30%HIGH2019-08-06

In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2019-2121

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9375

Open SourceCoalition ESS < 30%HIGH2019-08-21

In hostapd, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10...

CVEs:CVE-2019-9375

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9268

Open SourceCoalition ESS < 30%HIGH2019-08-21

In libstagefright, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation. Product...

CVEs:CVE-2019-9268

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-20988

GoogleEPSS <= 49%HIGH2019-08-22

The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.

CVEs:CVE-2018-20988

Affected products

ProductStatusVendorPackageEcosystem
google_forms affected google_forms_project
Upstream advisory

CVE-2016-10880

GoogleEPSS <= 49%CRITICAL2019-08-14

The google-document-embedder plugin before 2.6.1 for WordPress has XSS.

CVEs:CVE-2016-10880

Affected products

ProductStatusVendorPackageEcosystem
google_doc_embedder affected google_doc_embedder_project
Upstream advisory

CVE-2016-10881

GoogleEPSS <= 49%CRITICAL2019-08-14

The google-document-embedder plugin before 2.6.2 for WordPress has XSS.

CVEs:CVE-2016-10881

Affected products

ProductStatusVendorPackageEcosystem
google_doc_embedder affected google_doc_embedder_project
Upstream advisory

CVE-2016-10870

GoogleEPSS <= 49%CRITICAL2019-08-13

The google-language-translator plugin before 5.0.06 for WordPress has XSS.

CVEs:CVE-2016-10870

Affected products

ProductStatusVendorPackageEcosystem
google_language_translator affected gtranslate
Upstream advisory

CVE-2009-5158

GoogleEPSS <= 49%MEDIUM2019-08-22

The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.

CVEs:CVE-2009-5158

Affected products

ProductStatusVendorPackageEcosystem
google_analyticator affected sumo
Upstream advisory

CVE-2016-10882

GoogleEPSS <= 49%HIGH2019-08-14

The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.

CVEs:CVE-2016-10882

Affected products

ProductStatusVendorPackageEcosystem
google_doc_embedder affected google_doc_embedder_project
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.