Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-11012 Out-of-bounds Write vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_ENCRYPTION_TEST cfg80211 vendor command a stack-based buffer overflow can occur.
local
low complexity
google CWE-787
7.8
2017-11-14 CVE-2017-6275 Information Exposure vulnerability in Google Android
An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from an arbitrary kernel address.
network
low complexity
google CWE-200
7.5
2017-11-14 CVE-2017-6274 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
An elevation of Privilege vulnerability exists in the Thermal Driver, where a missing bounds checks in the thermal throttle driver can cause an out-of-bounds write in the kernel.
network
low complexity
google CWE-119
critical
9.8
2017-10-18 CVE-2014-3164 NULL Pointer Dereference vulnerability in Google Android
cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers to cause a denial of service (NULL pointer dereference, or out-of-bounds write) via vectors related to binder passed lengths.
network
low complexity
google CWE-476
7.5
2017-10-10 CVE-2017-9717 Out-of-bounds Read vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing Netlink attributes, a buffer overread can occur.
network
low complexity
google CWE-125
7.5
2017-10-10 CVE-2017-9715 Out-of-bounds Read vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a vendor command, a buffer over-read can occur.
network
low complexity
google CWE-125
7.5
2017-10-10 CVE-2017-9714 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an out of bound memory access may happen in limCheckRxRSNIeMatch in case incorrect RSNIE is received from the client in assoc request.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-9706 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an array out-of-bounds access can potentially occur in a display driver.
local
low complexity
google CWE-119
7.8
2017-10-10 CVE-2017-9697 Race Condition vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while reading command registration table entries in diag_dbgfs_read_table.
local
high complexity
google CWE-362
7.0
2017-10-10 CVE-2017-9687 Double Free vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, two concurrent threads/processes can write the value of "0" to the debugfs file that controls ipa ipc log which will lead to the double-free in ipc_log_context_destroy().
local
low complexity
google CWE-415
7.8