rpm package
suse/libvpx&distro=SUSE Linux Enterprise Module for Desktop Applications 15
pkg:rpm/suse/libvpx&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-9433 | Med | 6.5 | < 1.6.1-6.3.1 | 1.6.1-6.3.1 | Sep 27, 2019 | In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A- | |
| CVE-2019-9371 | Med | 6.5 | < 1.6.1-6.3.1 | 1.6.1-6.3.1 | Sep 27, 2019 | In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-13278325 | |
| CVE-2019-9325 | Med | 6.5 | < 1.6.1-6.3.1 | 1.6.1-6.3.1 | Sep 27, 2019 | In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-1120013 | |
| CVE-2019-9232 | Hig | 7.5 | < 1.6.1-6.3.1 | 1.6.1-6.3.1 | Sep 27, 2019 | In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122 | |
| CVE-2019-2126 | Hig | 8.8 | < 1.6.1-6.3.1 | 1.6.1-6.3.1 | Aug 20, 2019 | In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Version |
- affected < 1.6.1-6.3.1fixed 1.6.1-6.3.1
In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-
- affected < 1.6.1-6.3.1fixed 1.6.1-6.3.1
In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-13278325
- affected < 1.6.1-6.3.1fixed 1.6.1-6.3.1
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-1120013
- affected < 1.6.1-6.3.1fixed 1.6.1-6.3.1
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122
- affected < 1.6.1-6.3.1fixed 1.6.1-6.3.1
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Version