MEDIUM🇬🇧 English

CVE-2019-13098

CVSS 6.5v3.0pub. 2019-07-22upd. 2024-11-21

The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications.

oryginał EN
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Google Android

    OS
    Google
    < 4.1
  • Tronlink Wallet

    APP
    Tronlink
    2.2.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-16010CRITICAL9.6⚠ KEVPL ✓ten sam produkt

Heap buffer overflow w Google Chrome na Android — sandbox escape

CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku

CVE-2026-78937CRITICAL9.6ten sam produkt

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...

CVE-2026-76036CRITICAL9.6ten sam produkt

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to ex...

CVE-2026-19157CRITICAL9.6PL ✓ten sam produkt

Out-of-bounds write w ANGLE umożliwia sandbox escape w Chrome na Android