CVE-2019-2179 PUBLISHED CVSS 5.5 MEDIUM

In NDEF_MsgValidate of ndef_utils in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

EPSS 0.06% · 19.2th percentile

Risk Scores

CVSS v3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.06%
19.2th percentile

Affected Products

VendorProductVersions
googleandroid7.1.1, 7.1.2, 8.0
n/aAndroidAndroid-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9

Timeline

References

Open in Interactive Console →