CVE-2019-2162
published 2019-09-27CVE-2019-2162: In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.73%
50.8th percentile
In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112713720
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fx5p-4v4c-vq9q: In libxaac there is a possible out of bounds read due to a missing bounds check
ghsa_unreviewed·2022-05-24
CVE-2019-2162 [MEDIUM] GHSA-fx5p-4v4c-vq9q: In libxaac there is a possible out of bounds read due to a missing bounds check
In libxaac there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112713720
Red Hat
struts2: unsanitized text in the Locale object constructed by I18NInterceptor
vendor_redhat·2016-04-13·CVSS 6.1
CVE-2016-2162 [MEDIUM] CWE-79 struts2: unsanitized text in the Locale object constructed by I18NInterceptor
struts2: unsanitized text in the Locale object constructed by I18NInterceptor
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google G
No detection rules found.
No public exploits indexed.
2019-09-27
Published