Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-11040 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
local
low complexity
google CWE-200
5.5
2017-09-21 CVE-2017-11002 Out-of-bounds Read vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.
local
low complexity
google CWE-125
5.5
2017-09-21 CVE-2017-11001 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
local
low complexity
google CWE-200
5.5
2017-09-21 CVE-2017-11000 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.
local
low complexity
google CWE-119
7.8
2017-09-21 CVE-2017-10999 Unspecified vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.
local
low complexity
google
7.8
2017-09-21 CVE-2017-10998 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is fully within the valid region.
local
low complexity
google CWE-119
7.8
2017-09-21 CVE-2017-10997 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.
local
low complexity
google CWE-119
7.8
2017-09-21 CVE-2017-10996 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated.
local
low complexity
google CWE-200
5.5
2017-09-15 CVE-2015-1527 Integer Overflow or Wraparound vulnerability in Google Android
Integer overflow in IAudioPolicyService.cpp in Android allows local users to gain privileges via a crafted application, aka Android Bug ID 19261727.
local
low complexity
google CWE-190
7.8
2017-09-14 CVE-2017-0785 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android system (bluetooth).
low complexity
google CWE-200
6.5