Vulnerabilities > Google > Android > 8.1

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2017-13198 Improper Input Validation vulnerability in Google Android
A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map.
network
low complexity
google CWE-20
7.8
2018-01-12 CVE-2017-13197 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error.
network
low complexity
google CWE-119
7.8
2018-01-12 CVE-2017-13196 Missing Release of Resource after Effective Lifetime vulnerability in Google Android
In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could lead to memory leaks.
network
low complexity
google CWE-772
7.8
2018-01-12 CVE-2017-13195 Infinite Loop vulnerability in Google Android
In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead to negative indexes which could lead to an infinite loop.
network
low complexity
google CWE-835
7.8
2018-01-12 CVE-2017-13194 Improper Input Validation vulnerability in multiple products
A vulnerability in the Android media framework (libvpx) related to odd frame width.
network
low complexity
google debian CWE-20
7.8
2018-01-12 CVE-2017-13193 Infinite Loop vulnerability in Google Android
In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the same sps being fed in over and over.
network
low complexity
google CWE-835
7.8
2018-01-12 CVE-2017-13192 Infinite Loop vulnerability in Google Android
In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an infinite loop.
network
low complexity
google CWE-835
7.8
2018-01-12 CVE-2017-13191 Infinite Loop vulnerability in Google Android
In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error.
network
low complexity
google CWE-835
7.8
2018-01-12 CVE-2017-13190 Allocation of Resources Without Limits or Throttling vulnerability in Google Android
A vulnerability in the Android media framework (libhevc) related to handling ps_codec_obj memory allocation failures.
network
low complexity
google CWE-770
7.8
2018-01-12 CVE-2017-13189 Allocation of Resources Without Limits or Throttling vulnerability in Google Android
A vulnerability in the Android media framework (libavc) related to handling dec_hdl memory allocation failures.
network
low complexity
google CWE-770
7.8