CVE-2019-5236

UnknownEPSS 0.58%

Last modified

CVE-2019-5236 is a vulnerability of currently unknown severity. Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick a user to click a URL to exploit this vulnerability. EPSS estimates a 0.58% chance of exploitation in the next 30 days.

Description

Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick a user to click a URL to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.

Metrics

EPSS Probability
0.58%

43.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiEmily-L29c Firmware8.1.0.132a\(c432\)
HuaweiEmily-L29c Firmware8.1.0.135\(c782\)
HuaweiEmily-L29c Firmware8.1.0.154\(c10\)
HuaweiEmily-L29c Firmware8.1.0.154\(c461\)
HuaweiEmily-L29c Firmware8.1.0.154\(c635\)
HuaweiEmily-L29c Firmware8.1.0.156\(c185\)
HuaweiEmily-L29c Firmware8.1.0.156\(c605\)
HuaweiEmily-L29c Firmware8.1.0.159\(c636\)

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-5236?
Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick a user to click a URL to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.
How severe is CVE-2019-5236?
Severity scoring for CVE-2019-5236 is pending analysis. The EPSS model estimates a 0.58% probability of exploitation in the next 30 days.
How do I fix CVE-2019-5236?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-5236?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST