6.8
CVSSv2

CVE-2019-2029

Published: 19/04/2019 Updated: 21/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-120612744.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 7.1.2

google android 8.0

google android 8.1

google android 9.0

google android 7.1.1

google android 7.0

Recent Articles

Don't be an April Fool: Update your Android mobes, gizmos to – hopefully – pick up critical security fixes
The Register • Shaun Nichols in San Francisco • 02 Apr 2019

Meanwhile, another Edge, IE zero-day emitted online Hey, what's Mandarin for 'WTF is going on?' Nokia phones caught spewing device IDs to China

Google has released the April edition of its monthly Android security updates, including fixes for three remote-code execution vulnerabilities in the mobile OS. This month's batch – now out for Google-branded devices, at least: other Android device manufacturers and carriers push out updates on on their own – includes one batch of fixes for 11 CVE-listed vulnerabilities that everyone should apply, and a second batch for 44 flaws, that should be applied depending on your device's hardware and...