CVE-2019-2003
Last modified
CVE-2019-2003 is a vulnerability of currently unknown severity. In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-116321860
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 7.0 | |
| Android | 7.1.1 | |
| Android | 7.1.2 | |
| Android | 8.0 | |
| Android | 8.1 | |
| Android | 9.0 |
References
- https://source.android.com/security/bulletin/2019-03-01Vendor Advisory
- https://source.android.com/security/bulletin/2019-03-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-2003?
How severe is CVE-2019-2003?
How do I fix CVE-2019-2003?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-20024A heap-based buffer overflow was discovered in image_buffer_…6.5
- CVE-2019-20025Certain builds of NEC SV9100 software could allow an unauthe…9.8
- CVE-2019-20026The WebPro interface in NEC SV9100 software releases 7.0 or …7.5
- CVE-2019-20027Aspire-derived NEC PBXes, including the SV8100, SV9100, SL11…9.8
- CVE-2019-20028Aspire-derived NEC PBXes operating InMail software, includin…7.5
- CVE-2019-20029An exploitable privilege escalation vulnerability exists in …8.8
- CVE-2019-20030An attacker with knowledge of the modem access number on a N…7.8
- CVE-2019-20031NEC UM8000, UM4730 and prior non-InMail voicemail systems wi…9.1
- CVE-2019-20032An attacker with access to an InMail voicemail box equipped …6.5
- CVE-2019-20033On Aspire-derived NEC PBXes, including all versions of SV810…9.8
- CVE-2019-2004In publishKeyEvent, publishMotionEvent and sendUnchainedFini…
- CVE-2019-20041wp_kses_bad_protocol in wp-includes/kses.php in WordPress be…9.8
Are you affected by CVE-2019-2003?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
