Vulnerabilities > Google > Android > 8.1

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2017-13209 Missing Authorization vulnerability in Google Android 8.0/8.1
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service.
local
low complexity
google CWE-862
7.2
2018-01-12 CVE-2017-13208 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response.
network
low complexity
google CWE-119
critical
10.0
2018-01-12 CVE-2017-13206 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (aacdec).
network
low complexity
google CWE-200
5.0
2018-01-12 CVE-2017-13205 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libmpeg2).
network
low complexity
google CWE-200
8.5
2018-01-12 CVE-2017-13204 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libavc).
network
low complexity
google CWE-200
8.5
2018-01-12 CVE-2017-13203 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libavc).
network
low complexity
google CWE-200
8.5
2018-01-12 CVE-2017-13202 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libeffects).
network
low complexity
google CWE-200
5.0
2018-01-12 CVE-2017-13201 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (mediadrm).
network
low complexity
google CWE-200
5.0
2018-01-12 CVE-2017-13200 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (av) related to id3 unsynchronization.
network
low complexity
google CWE-200
5.0
2018-01-12 CVE-2017-13199 Improper Handling of Exceptional Conditions vulnerability in Google Android 8.0/8.1
In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException later on.
network
low complexity
google CWE-755
7.8