Total
34640 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-15400 | 1 Asus | 2 Zenfone 3 Ultra, Zenfone 3 Ultra Firmware | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The Asus ZenFone 3 Ultra Android device with a build fingerprint of asus/WW_Phone/ASUS_A001:7.0/NRD90M/14.1010.1804.75-20180612:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions th ...
Show More |
|||||
| CVE-2019-15399 | 1 Asus | 2 Zenfone 5q, Zenfone 5q Firmware | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The Asus ZenFone 5Q Android device with a build fingerprint of asus/WW_Phone/ASUS_X017D_2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions t ...
Show More |
|||||
| CVE-2019-15398 | 1 Asus | 2 Zenfone 4 Selfie, Zenfone 4 Selfie Firmware | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Z01M/ASUS_Z01M_1:7.1.1/NMF26F/WW_user_11.40.208.77_20170922:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permi ...
Show More |
|||||
| CVE-2019-15397 | 1 Asus | 2 Zenfone Max 4, Zenfone Max 4 Firmware | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The Asus ZenFone Max 4 Android device with a build fingerprint of asus/WW_Phone/ASUS_X00HD_4:7.1.1/NMF26F/14.2016.1803.373-20180308:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permission ...
Show More |
|||||
| CVE-2019-15396 | 1 Asus | 2 Zenfone 3, Zenfone 3 Firmware | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The Asus ZenFone 3 Android device with a build fingerprint of asus/WW_Phone/ASUS_Z012D:7.0/NRD90M/14.2020.1708.56-20170719:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that ar ...
Show More |
|||||
| CVE-2019-15395 | 1 Asus | 2 Zenfone 3s Max, Zenfone 3s Max Firmware | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The Asus ZenFone 3s Max Android device with a build fingerprint of asus/IN_X00G/ASUS_X00G_1:7.0/NRD90M/IN_X00G-14.02.1807.33-20180706:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000015, versionName=7.0.0.3_161222) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissi ...
Show More |
|||||
| CVE-2019-15392 | 1 Asus | 2 Zenfone 4 Selfie, Zenfone 4 Selfie Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Asus ZenFone 4 Selfie Android device with a build fingerprint of Android/sdm660_64/sdm660_64:8.1.0/OPM1/14.2016.1802.247-20180419:user/release-keys contains a pre-installed app with a package name of com.log.logservice app (versionCode=1, versionName=1) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15391 | 1 Asus | 2 Zenfone 4 Selfie, Zenfone 4 Selfie Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Phone/ASUS_X00LD_1:8.1.0/OPM1.171019.011/15.0400.1809.405-0:user/release-keys contains a pre-installed app with a package name of com.log.logservice app (versionCode=1, versionName=1) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15390 | 1 Haier G8 Project | 2 Haier G8, Haier G8 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Haier G8 Android device with a build fingerprint of Haier/HM-G559-FL/G8:8.1.0/O11019/1522294799:user/release-keys contains a pre-installed app with a package name of com.qiku.service.container app (versionCode=5, versionName=1.03.00_VER_32525983298984) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15389 | 1 Haier A6 Project | 2 Haier A6, Haier A6 Firmware | 2024-11-21 | 9.3 HIGH | 8.1 HIGH |
|
The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be perf ...
Show More |
|||||
| CVE-2019-15385 | 1 Infinixmobility | 2 Note 5, Note 5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Infinix Note 5 Android device with a build fingerprint of Infinix/H633B/Infinix-X604_sprout:8.1.0/O11019/L-IN-180206V64:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15384 | 1 Elephone | 2 A4, A4 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Elephone A4 Android device with a build fingerprint of Elephone/A4/A4:8.1.0/O11019/20180530.143559:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15383 | 1 Allviewmobile | 2 Soul X5, Soul X5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Allview X5 Android device with a build fingerprint of ALLVIEW/X5_Soul_Mini/X5_Soul_Mini:8.1.0/O11019/1522468763:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15382 | 1 Cubot | 2 Nova, Nova Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Cubot Nova Android device with a build fingerprint of CUBOT/CUBOT_NOVA/CUBOT_NOVA:8.1.0/O11019/1527060122:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15381 | 1 Bq | 2 5515l, 5515l Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The BQ 5515L Android device with a build fingerprint of BQru/BQru-5515L/BQru-5515L:8.1.0/O11019/20180409.195525:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15380 | 1 Fly-phone | 2 Photo Pro, Photo Pro Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Fly Photo Pro Android device with a build fingerprint of Fly/PhotoPro/Photo_Pro:8.1.0/O11019/1528117003:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15379 | 1 Waltonbd | 2 Primo G3, Primo G3 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Walton Primo G3 Android device with a build fingerprint of WALTON/Primo_GM3/Primo_GM3:8.1.0/O11019/1522737198:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15378 | 1 Panasonic | 2 Eluga Ray 600, Eluga Ray 600 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Panasonic Eluga Ray 600 Android device with a build fingerprint of Panasonic/ELUGA_Ray_600/ELUGA_Ray_600:8.1.0/O11019/1532692680:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15377 | 1 Cherrymobile | 2 Flare S7, Flare S7 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Cherry Flare S7 Android device with a build fingerprint of Cherry_Mobile/Flare_S7_Deluxe/Flare_S7_Deluxe:8.1.0/O11019/1533920920:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15376 | 1 Panasonic | 2 Eluga Ray 530, Eluga Ray 530 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Panasonic Eluga Ray 530 Android device with a build fingerprint of Panasonic/ELUGA_Ray_530/ELUGA_Ray_530:8.1.0/O11019/1531828974:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15375 | 1 Haier | 2 G8, G8 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Haier G8 Android device with a build fingerprint of Haier/HM-G559-FL/G8:8.1.0/O11019/1522294799:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15374 | 1 Lavamobiles | 2 Iris 88 Lite, Iris 88 Lite Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15373 | 1 Symphony-mobile | 2 I95 Lite, I95 Lite Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Symphony i95 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15372 | 1 Hisense | 2 Infinity F17, Infinity F17 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Hisense F17 Android device with a build fingerprint of Hisense/F17_4G/HS6739MT:8.1.0/O11019/Hisense_F17_4G_00_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15371 | 1 Symphony-mobile | 2 G100, G100 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Symphony G100 Android device with a build fingerprint of Symphony/G100/G100:8.1.0/O11019/1530618779:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15370 | 1 Haier G8 Project | 2 Haier G8, Haier G8 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Haier G8 Android device with a build fingerprint of Haier/HM-G559-FL/G8:8.1.0/O11019/1526527761:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15369 | 1 Lavamobiles | 2 Z61 Turbo, Z61 Turbo Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15368 | 1 Coolpad | 2 Mega 5, Mega 5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15367 | 1 Haier | 2 P10, P10 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Haier P10 Android device with a build fingerprint of Haier/P10/P10:8.1.0/O11019/1532662449:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15366 | 1 Infinixmobility | 2 Note 5, Note 5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Infinix Note 5 Android device with a build fingerprint of Infinix/H633IJL/Infinix-X604_sprout:8.1.0/O11019/IJL-180531V181:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15365 | 1 Lavamobiles | 2 Z92, Z92 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15364 | 1 Dexp | 2 Bl250, Bl250 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Dexp BL250 Android device with a build fingerprint of DEXP/BL250/BL250:8.1.0/O11019/1530858027:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15363 | 1 Leagoo | 2 Power 5, Power 5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Leagoo Power 5 Android device with a build fingerprint of LEAGOO/Power_5/Power_5:8.1.0/O11019/1532686195:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15362 | 1 Lavamobiles | 2 Iris 88, Iris 88 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15361 | 1 Infinixmobility | 2 Note 5, Note 5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Infinix Note 5 Android device with a build fingerprint of Infinix/H632C/Infinix-X605_sprout:8.1.0/O11019/CE-180914V59:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15360 | 1 Hisense | 2 Infinity U965, Infinity U965 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Hisense U965 Android device with a build fingerprint of Hisense/U965_4G_10/HS6739MT:8.1.0/O11019/Hisense_U965_4G_10_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15359 | 1 Haier | 2 A6, A6 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15358 | 1 Dexp | 2 Z250, Z250 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Dexp Z250 Android device with a build fingerprint of DEXP/Z250/Z250:8.1.0/O11019/1531130719:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15357 | 1 Advandigital | 2 I6a, I6a Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Advan i6A Android device with a build fingerprint of ADVAN/i6A/i6A:8.1.0/O11019/1523602705:userdebug/test-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15356 | 1 Lavamobiles | 2 Flair Z1, Flair Z1 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||