CVE-2019-2109
published 2019-07-08CVE-2019-2109: In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote…
PriorityP347high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.20%
64.7th percentile
In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-130651570.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q344-2h3j-jfp5: In MakeMPEG4VideoCodecSpecificData of AVIExtractor
ghsa_unreviewed·2022-05-24
CVE-2019-2109 [HIGH] CWE-787 GHSA-q344-2h3j-jfp5: In MakeMPEG4VideoCodecSpecificData of AVIExtractor
In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-130651570.
OSV
CVE-2019-2109: In MakeMPEG4VideoCodecSpecificData of AVIExtractor
osv·2019-07-08·CVSS 8.8
CVE-2019-2109 [HIGH] CVE-2019-2109: In MakeMPEG4VideoCodecSpecificData of AVIExtractor
In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-130651570.
Android
CVE-2019-2109: Android Security Bulletin 2019-07-01
CVE: CVE-2019-2109
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7
vendor_android·2019-07-01·CVSS 8.8
CVE-2019-2109 [HIGH] CVE-2019-2109: Android Security Bulletin 2019-07-01
CVE: CVE-2019-2109
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7
Android Security Bulletin 2019-07-01
CVE: CVE-2019-2109
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1
References: A-130651570*
Suricata
ET EXPLOIT Zimbra <8.8.11 - XML External Entity Injection/SSRF Attempt (CVE-2019-9621)
suricata·2021-01-27·CVSS 7.5
CVE-2019-9621 [HIGH] ET EXPLOIT Zimbra <8.8.11 - XML External Entity Injection/SSRF Attempt (CVE-2019-9621)
ET EXPLOIT Zimbra $HOME_NET any (msg:"ET EXPLOIT Zimbra "; content:""; reference:url,www.exploit-db.com/exploits/46967; reference:url,packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html; reference:cve,2019-9621; reference:cve,2021-2109; classtype:attempted-user; sid:2031562; rev:1; metadata:affected_product Web_Server_Applications, attack_target Client_Endpoint, created_at 2021_01_27, cve CVE_2021_2109, deployment Perimeter, confidence Medium, signature_severity Major, updated_at 2021_01_27;)
No public exploits indexed.
No writeups or analysis indexed.
2019-07-08
Published