CVE-2019-2009
published 2019-06-19CVE-2019-2009: In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over…
PriorityP347high8.8CVSS 3.0
AVAACLPRNUINSUCHIHAH
EPSS
0.61%
45.2th percentile
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120665616
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xg9w-79qq-wr22: In l2c_lcc_proc_pdu of l2c_fcr
ghsa_unreviewed·2022-05-24
CVE-2019-2009 [HIGH] CWE-787 GHSA-xg9w-79qq-wr22: In l2c_lcc_proc_pdu of l2c_fcr
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120665616
Android
CVE-2019-2009: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2009
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7
vendor_android·2019-03-01·CVSS 8.8
CVE-2019-2009 [HIGH] CVE-2019-2009: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2009
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7
Android Security Bulletin 2019-03-01
CVE: CVE-2019-2009
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-120665616
No detection rules found.
Exploit-DB
CompleteFTP Professional 12.1.3 - Remote Code Execution
exploitdb·2020-07-09·CVSS 4.3
CVE-2019-16116 [MEDIUM] CompleteFTP Professional 12.1.3 - Remote Code Execution
CompleteFTP Professional 12.1.3 - Remote Code Execution
---
# Exploit Title: CompleteFTP Professional
""".strip()
# endregion
# region update_config
update_config = """
{XMLSCHEMA}
{XMLDIFFGRAM}
2
0
-1
-1
""".strip()
# endregion
# region xml_schema
xml_schema = """
""".replace("", ">").replace('"', """).strip()
# endregion
# region xml_diffgram
xml_diffgram = """
88428040-73b3-4497-9b6d-69af2f1cc3c7
Process Execution
EnterpriseDT.Net.FtpServer.Trigger.ProcessTrigger
2
{CONFIGURATION}
2020-03-10T18:33:41.107+08:00
2020-03-10T10:52:00.7496654+08:00
false
true
{ID}
2
Event
2009-06-29T11:48:00+08:00
2009-06-29T11:48:00+08:00
3
2020-03-10T10:50:44.4209655+08:00
2020-03-10T10:50:44.4209655+08:
Exploit-DB
Apache Olingo OData 4.0 - XML External Entity Injection
exploitdb·2019-12-11·CVSS 5.5
CVE-2019-17554 [MEDIUM] Apache Olingo OData 4.0 - XML External Entity Injection
Apache Olingo OData 4.0 - XML External Entity Injection
---
#############################################################
#
# COMPASS SECURITY ADVISORY
# https://www.compass-security.com/research/advisories/
#
#############################################################
#
# Product: Apache Olingo OData 4.0
# Vendor: Apache Foundation
# CSNC ID: CSNC-2009-025
# CVE ID: CVE-2019-17554
# Subject: XML External Entity Resolution (XXE)
# Risk: High
# Effect: Remotely exploitable
# Author: Archibald Haddock ([email protected])
# Date: 08.11.2019
#
#############################################################
Introduction:
Apache Olingo is a Java library that implements the Open Data Protocol (OData). [1]
XML data is parsed by insecurley configured software components, which can
2019-06-19
Published