CVE-2019-5305
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The image processing module of some Huawei Mate 10 smartphones versions before ALP-L29 9.0.0.159(C185) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which could trigger double free and cause a system crash.
El módulo de procesamiento de imágenes de algunas versiones de teléfonos inteligentes Mate 10 de Huawei anteriores a ALP-L29 9.0.0.159 (C185), presentan una vulnerabilidad de doble liberación de memoria (double free). Un atacante engaña a un usuario para instalar una aplicación maliciosa, y la aplicación puede llamar a una API especial, lo que podría desencadenar una doble liberación y causar un bloqueo del sistema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-04 CVE Reserved
- 2019-06-06 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190128-01-ivp-en | 2019-06-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Mate 10 Firmware Search vendor "Huawei" for product "Mate 10 Firmware" | < alp-l29_9.0.0.159\(c185\) Search vendor "Huawei" for product "Mate 10 Firmware" and version " < alp-l29_9.0.0.159\(c185\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 10 Search vendor "Huawei" for product "Mate 10" | - | - |
Safe
|