CVE-2019-2087
published 2019-09-27CVE-2019-2087: In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.71%
49.6th percentile
In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118149009
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cr75-2qq3-cwjw: In libxaac, there is a possible out of bounds write due to a missing bounds check
ghsa_unreviewed·2022-05-24
CVE-2019-2087 [HIGH] CWE-787 GHSA-cr75-2qq3-cwjw: In libxaac, there is a possible out of bounds write due to a missing bounds check
In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-118149009
Red Hat
struts: Multiple XSS flaws in component handlers in javatemplates plug-in
vendor_redhat·2011-03-23·CVSS 4.3
CVE-2011-2087 [MEDIUM] CWE-79 struts: Multiple XSS flaws in component handlers in javatemplates plug-in
struts: Multiple XSS flaws in component handlers in javatemplates plug-in
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-27
Published