Vulnerabilities > Google > Android > 8.1

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2017-13188 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (aac).
network
low complexity
google CWE-200
8.5
2018-01-12 CVE-2017-13187 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android media framework (libhevc).
network
low complexity
google CWE-200
8.5
2018-01-12 CVE-2017-13186 Improper Input Validation vulnerability in Google Android
A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters.
network
low complexity
google CWE-20
7.8
2018-01-12 CVE-2017-13184 Use After Free vulnerability in Google Android 8.0/8.1
In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyncInjector.
local
low complexity
google CWE-416
7.2
2018-01-12 CVE-2017-13183 Race Condition vulnerability in Google Android 8.1
In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free due to a race condition if the user frees the buffer while it's being used in another thread.
local
high complexity
google CWE-362
6.2
2018-01-12 CVE-2017-13182 Integer Overflow or Wraparound vulnerability in Google Android 8.0/8.1
In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write.
local
low complexity
google CWE-190
7.2
2018-01-12 CVE-2017-13181 Double Free vulnerability in Google Android
In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer.
local
low complexity
google CWE-415
7.2
2018-01-12 CVE-2017-13180 Use After Free vulnerability in Google Android
In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing.
local
low complexity
google CWE-416
7.2
2018-01-12 CVE-2017-13179 Use After Free vulnerability in Google Android
In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free.
network
low complexity
google CWE-416
critical
10.0
2018-01-12 CVE-2017-13178 Use After Free vulnerability in Google Android
In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails.
network
low complexity
google CWE-416
critical
10.0