Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-0842 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
An elevation of privilege vulnerability in the Android system (bluetooth).
local
low complexity
google CWE-119
7.8
2017-11-16 CVE-2017-9721 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the boot loader, a buffer overflow can occur while parsing the splash image.
local
low complexity
google CWE-119
7.8
2017-11-16 CVE-2017-9719 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the kernel driver MDSS, a buffer overflow can occur in HDMI CEC parsing if frame size is out of range.
local
low complexity
google CWE-119
7.8
2017-11-16 CVE-2017-9696 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer over-read is possible in camera driver function msm_isp_stop_stats_stream.
network
low complexity
google CWE-119
7.5
2017-11-16 CVE-2017-11029 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer, which resides in user space.
local
low complexity
google CWE-119
7.8
2017-11-16 CVE-2017-11018 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, array access out of bounds may occur in the camera driver in the kernel
local
low complexity
google CWE-119
7.8
2017-11-16 CVE-2017-11017 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a specially crafted UBI image, it is possible to corrupt memory, or access uninitialized memory.
local
low complexity
google CWE-119
7.8
2017-11-16 CVE-2017-0866 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nvidia Tegra X1 Firmware
An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree.
local
low complexity
nvidia CWE-119
7.8
2017-11-16 CVE-2017-16844 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Procmail 3.22
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
network
low complexity
procmail CWE-119
critical
9.8
2017-11-16 CVE-2017-8807 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.
network
low complexity
varnish-cache varnish-cache-project debian CWE-119
critical
9.1