Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2017-12-05 CVE-2017-11045 Use After Free vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a camera driver function, a race condition exists which can lead to a Use After Free condition.
local
high complexity
google CWE-416
7.0
2017-12-05 CVE-2017-11044 Use After Free vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a KGSL driver function, a race condition exists which can lead to a Use After Free condition.
local
high complexity
google CWE-416
7.0
2017-12-05 CVE-2017-11042 Missing Authorization vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, ImsService and the IQtiImsExt AIDL APIs are not subject to access control.
local
low complexity
google CWE-862
7.8
2017-12-05 CVE-2017-11033 Use After Free vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the coresight-tmc driver, a simultaneous read and enable of the ETR device after changing the buffer size may result in a Use After Free condition of the previous buffer.
local
low complexity
google CWE-416
7.8
2017-12-05 CVE-2017-11031 Use After Free vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the VIDIOC_G_SDE_ROTATOR_FENCE ioctl command can be used to cause a Use After Free condition.
network
low complexity
google CWE-416
7.5
2017-12-05 CVE-2017-11030 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the HDMI video driver function hdmi_edid_sysfs_rda_res_info(), userspace can perform an arbitrary write into kernel memory.
local
low complexity
google CWE-119
7.8
2017-12-05 CVE-2017-11019 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the fd allocated during the get_metadata was not closed even though the buffer allocated to the fd was freed.
local
low complexity
google CWE-119
7.8
2017-12-05 CVE-2017-11016 Improper Resource Shutdown or Release vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when memory allocation fails while creating a calibration block in create_cal_block stale pointers are left uncleared.
local
low complexity
google CWE-404
7.8
2017-11-16 CVE-2017-0865 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the MediaTek soc driver.
local
low complexity
google
7.8
2017-11-16 CVE-2017-0864 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the MediaTek ioctl (flashlight).
local
low complexity
google
7.8