Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2018-02-12 CVE-2017-13233 Resource Exhaustion vulnerability in Google Android
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion.
network
low complexity
google CWE-400
6.5
2018-02-12 CVE-2017-13232 Out-of-bounds Write vulnerability in Google Android
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated.
network
low complexity
google CWE-787
7.5
2018-02-12 CVE-2017-13231 Out-of-bounds Write vulnerability in Google Android 8.0/8.1
In libmediadrm, there is an out-of-bounds write due to improper input validation.
local
low complexity
google CWE-787
7.8
2018-02-12 CVE-2017-13230 Out-of-bounds Write vulnerability in Google Android
In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value.
network
low complexity
google CWE-787
8.8
2018-02-12 CVE-2017-13229 Improper Input Validation vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (n/a).
network
low complexity
google CWE-20
critical
9.8
2018-02-12 CVE-2017-13228 Out-of-bounds Write vulnerability in Google Android
In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character.
network
low complexity
google CWE-787
8.8
2018-02-06 CVE-2017-6279 Out-of-bounds Write vulnerability in Google Android
NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process.
local
low complexity
google CWE-787
7.8
2018-02-06 CVE-2017-6258 Out-of-bounds Write vulnerability in Google Android
NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process.
local
low complexity
google CWE-787
7.8
2018-01-23 CVE-2016-5345 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via a crafted application, aka Android internal bug 32639452 and Qualcomm internal bug CR1079713.
local
high complexity
google CWE-119
7.0
2018-01-18 CVE-2017-17860 Improper Input Validation vulnerability in Google Android
In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key.
low complexity
google CWE-20
5.7