Vulnerabilities > Google > Android > 6.0.1

DATE CVE VULNERABILITY TITLE RISK
2018-11-06 CVE-2018-9358 Out-of-bounds Read vulnerability in Google Android
In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2018-11-06 CVE-2018-9357 Out-of-bounds Write vulnerability in Google Android
In BNEP_Write of bnep_api.cc, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
7.8
2018-11-06 CVE-2018-9356 Double Free vulnerability in Google Android
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free.
network
low complexity
google CWE-415
critical
9.8
2018-11-06 CVE-2018-9355 Out-of-bounds Write vulnerability in Google Android
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check.
network
low complexity
google CWE-787
critical
9.8
2018-08-17 CVE-2018-15482 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents.
network
low complexity
google CWE-732
critical
9.8
2018-08-17 CVE-2018-14982 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application.
network
low complexity
google CWE-732
critical
9.8
2018-08-17 CVE-2018-14981 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents.
network
low complexity
google CWE-732
critical
9.8
2018-08-07 CVE-2018-5383 Improper Verification of Cryptographic Signature vulnerability in multiple products
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
high complexity
google apple CWE-347
6.8
2018-07-06 CVE-2018-5907 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8
2018-07-06 CVE-2018-11304 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8