• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-15417
Spark Pro Firmware, Tecno
Spark_pro_firmware, Spark_pro
2020-08-24
N/A
7.8 HIGH
The Tecno Spark Pro Android device with a build fingerprint of TECNO/H3722/TECNO-K8:7.0/NRD90M/K8-H3722ABCDE-N-171229V96:user/release-keys contains a pre-installed app with a package name of com.lovelyfont.defcontainer app (versionCode=7, versionName=7.0.5) that allows unauthorized dynamic code loading via a confused deputy attack. This capability can be accessed by any app co-located on the device.
CVE-2019-15416
Sony, Xperia Xzs Firmware
Photo_sharing_plus, Kdl-50w800c, Kdl-50w805c, Kdl-50w807c, Kdl-50w809c, Kdl-50w820c, Kdl-55w800c, Kdl-55w805c, Kdl-65w850c, Kdl-65w855c
2020-08-24
N/A
7.8 HIGH
The Sony keyaki_kddi Android device with a build fingerprint of Sony/keyaki_kddi/keyaki_kddi:7.1.1/TONE3-3.0.0-KDDI-170517-0326/1:user/dev-keys contains a pre-installed app with a package name of com.kddi.android.packageinstaller app (versionCode=70008, versionName=08.10.03) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
CVE-2019-15415
Mi, Redmi 5 Firmware
M365_firmware, M365, Mi_5s_plus_firmware, Mi_5s_plus, Redmi_6_firmware, Redmi_6, Redmi_5_firmware, Redmi_5, 5s_plus_firmware, 5s_plus
2019-11-25
N/A
3.3 LOW
The Xiaomi Redmi 5 Android device with a build fingerprint of xiaomi/vince/vince:7.1.2/N2G47H/V9.5.4.0.NEGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1711_201803291645) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.
CVE-2019-15414
Asus, Zenfone Ar, Zenfone Ar Firmware
Hg100_firmware, Hg100, Zenfone_4_selfie_firmware, Zenfone_4_selfie, Zenfone_live_(l1)_firmware, Zenfone_live_(l1), Zenfone_5_selfie_firmware, Zenfone_5_selfie, Zenfone_3s_max_firmware, Zenfone_3s_max
2020-08-24
N/A
7.8 HIGH
The Asus ZenFone AR Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.splendidcommandagent app (versionCode=1510200105, versionName=1.2.0.21_180605) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
CVE-2019-15413
Asus, Zenfone 3 Ultra, Zenfone 3 Ultra Firmware
Hg100_firmware, Hg100, Zenfone_4_selfie_firmware, Zenfone_4_selfie, Zenfone_live_(l1)_firmware, Zenfone_live_(l1), Zenfone_5_selfie_firmware, Zenfone_5_selfie, Zenfone_3s_max_firmware, Zenfone_3s_max
2020-08-24
N/A
7.8 HIGH
The Asus ZenFone 3 Ultra Android device with a build fingerprint of asus/WW_Phone/ASUS_A001:7.0/NRD90M/14.1010.1804.75-20180612:user/release-keys contains a pre-installed app with a package name of com.asus.splendidcommandagent app (versionCode=1510200105, versionName=1.2.0.21_180605) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
CVE-2019-15412
Asus, Zenfone 4 Selfie, Zenfone 4 Selfie Firmware
Hg100_firmware, Hg100, Zenfone_4_selfie_firmware, Zenfone_4_selfie, Zenfone_live_(l1)_firmware, Zenfone_live_(l1), Zenfone_5_selfie_firmware, Zenfone_5_selfie, Zenfone_3s_max_firmware, Zenfone_3s_max
2020-08-24
N/A
7.8 HIGH
The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Z01M/ASUS_Z01M_1:7.1.1/NMF26F/WW_71.50.395.57_20180913:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
CVE-2019-15411
Asus, Zenfone 3 Laser, Zenfone 3 Laser Firmware
Hg100_firmware, Hg100, Zenfone_4_selfie_firmware, Zenfone_4_selfie, Zenfone_live_(l1)_firmware, Zenfone_live_(l1), Zenfone_5_selfie_firmware, Zenfone_5_selfie, Zenfone_3s_max_firmware, Zenfone_3s_max
2020-08-24
N/A
7.8 HIGH
The Asus ZenFone 3 Laser Android device with a build fingerprint of asus/WW_msm8937/msm8937:7.1.1/NMF26F/WW_32.40.106.114_20180928:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
CVE-2019-15410
Asus, Zenfone 5q, Zenfone 5q Firmware
Hg100_firmware, Hg100, Zenfone_4_selfie_firmware, Zenfone_4_selfie, Zenfone_live_(l1)_firmware, Zenfone_live_(l1), Zenfone_5_selfie_firmware, Zenfone_5_selfie, Zenfone_3s_max_firmware, Zenfone_3s_max
2020-08-24
N/A
7.8 HIGH
The Asus ZenFone 5Q Android device with a build fingerprint of asus/WW_Phone/ASUS_X017D_2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
CVE-2019-1541
2020-09-10
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during [2019]. Notes: none.
CVE-2019-15409
Asus, Zenfone 5q, Zenfone 5q Firmware
Hg100_firmware, Hg100, Zenfone_4_selfie_firmware, Zenfone_4_selfie, Zenfone_live_(l1)_firmware, Zenfone_live_(l1), Zenfone_5_selfie_firmware, Zenfone_5_selfie, Zenfone_3s_max_firmware, Zenfone_3s_max
2020-08-24
N/A
7.8 HIGH
The Asus ZenFone 5Q Android device with a build fingerprint of asus/WW_Phone/ASUS_X017D_2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
« Previous 1 … 6,118 6,119 6,120 6,121 6,122 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE