
CVE-2019-2027
https://notcve.org/view.php?id=CVE-2019-2027
19 Apr 2019 — In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. • https://source.android.com/security/bulletin/2019-04-01 • CWE-787: Out-of-bounds Write •

CVE-2019-2026
https://notcve.org/view.php?id=CVE-2019-2026
19 Apr 2019 — In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local escalation of privilege and FRP bypass with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0Android ID: A-120866126 Vulnerabilidad en la función updateAssistMenuItems del archivo editor.Java, hay un posible escape del asistente de instalación debido a una falta de comprobación de a... • https://source.android.com/security/bulletin/2019-04-01 • CWE-862: Missing Authorization •

CVE-2019-2023 – Android - getpidcon() Usage in Hardware binder ServiceManager Permits ACL Bypass
https://notcve.org/view.php?id=CVE-2019-2023
06 Mar 2019 — In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could allow an app to add or replace a HAL service with its own service, gaining code execution in a privileged process.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-121035042Upstream kernel En ServiceManager :: add function en el administrador de servicios de hardware, hay una verificación de permisos inseguros basada en el PID de la persona... • https://packetstorm.news/files/id/151990 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-1993
https://notcve.org/view.php?id=CVE-2019-1993
28 Feb 2019 — In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. • http://www.securityfocus.com/bid/106946 • CWE-190: Integer Overflow or Wraparound CWE-787: Out-of-bounds Write •

CVE-2019-1987
https://notcve.org/view.php?id=CVE-2019-1987
28 Feb 2019 — In onSetSampleX of SkSwizzler.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. • http://www.securityfocus.com/bid/106842 • CWE-787: Out-of-bounds Write •

CVE-2019-1988
https://notcve.org/view.php?id=CVE-2019-1988
28 Feb 2019 — In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. • http://www.securityfocus.com/bid/106842 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •

CVE-2019-1991
https://notcve.org/view.php?id=CVE-2019-1991
28 Feb 2019 — In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. • http://www.securityfocus.com/bid/106946 • CWE-787: Out-of-bounds Write •

CVE-2019-1992
https://notcve.org/view.php?id=CVE-2019-1992
28 Feb 2019 — In bta_hl_sdp_query_results of bta_hl_main.cc, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. • http://www.securityfocus.com/bid/106946 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-416: Use After Free •

CVE-2019-1994
https://notcve.org/view.php?id=CVE-2019-1994
28 Feb 2019 — In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. • http://www.securityfocus.com/bid/106946 • CWE-1188: Initialization of a Resource with an Insecure Default •

CVE-2019-1995
https://notcve.org/view.php?id=CVE-2019-1995
28 Feb 2019 — In ComposeActivityEmail of ComposeActivityEmail.java, there is a possible way to silently attach files to an email due to a confused deputy. This could lead to local information disclosure, sending files accessible to AOSP Mail to a remote email recipient, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. • http://www.securityfocus.com/bid/106946 •