Vulnerabilities > Google > Android > 6.0.1

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2017-13187 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libhevc).
network
low complexity
google CWE-200
critical
9.1
2018-01-12 CVE-2017-13186 Improper Input Validation vulnerability in Google Android
A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters.
network
low complexity
google CWE-20
7.5
2018-01-12 CVE-2017-13185 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libhevc).
network
low complexity
google CWE-200
critical
9.1
2018-01-12 CVE-2017-13180 Use After Free vulnerability in Google Android
In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing.
local
low complexity
google CWE-416
7.8
2018-01-12 CVE-2017-13179 Use After Free vulnerability in Google Android
In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free.
network
low complexity
google CWE-416
critical
9.8
2018-01-12 CVE-2017-13178 Use After Free vulnerability in Google Android
In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails.
network
low complexity
google CWE-416
critical
9.8
2018-01-12 CVE-2017-13177 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In several functions of libhevc, NEON registers are not preserved.
network
low complexity
google CWE-119
critical
9.8
2018-01-12 CVE-2017-13176 Improper Input Validation vulnerability in Google Android
In the parseURL function of URLStreamHandler, there is improper input validation of the host field.
network
low complexity
google CWE-20
8.8
2018-01-12 CVE-2017-0855 Missing Release of Resource after Effective Lifetime vulnerability in Google Android
In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks.
network
low complexity
google CWE-772
7.5
2018-01-12 CVE-2017-0846 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android framework (clipboardservice).
network
low complexity
google CWE-200
7.5