CVE-2019-2211 PUBLISHED CVSS 7.5 HIGH

In createProjectionMapForQuery of TvProvider.java, there is possible SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-135269669

EPSS 0.16% · 36.8th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.16%
36.8th percentile

Affected Products

VendorProductVersions
googleandroid8.0, 8.1, 9.0
n/aAndroidAndroid-8.0 Android-8.1 Android-9 Android-10

Timeline

References

Open in Interactive Console →