Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2018-12-07 CVE-2018-9572 Out-of-bounds Write vulnerability in Google Android 9.0
In impd_drc_parse_coeff of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check.
network
low complexity
google CWE-787
8.8
2018-12-07 CVE-2018-9571 Out-of-bounds Write vulnerability in Google Android 9.0
In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check.
network
low complexity
google CWE-787
8.8
2018-12-07 CVE-2018-9570 Out-of-bounds Write vulnerability in Google Android 9.0
In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check.
local
low complexity
google CWE-787
7.8
2018-12-07 CVE-2018-9569 Out-of-bounds Write vulnerability in Google Android 9.0
In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect bounds check.
network
low complexity
google CWE-787
8.8
2018-12-07 CVE-2018-9518 Out-of-bounds Write vulnerability in multiple products
In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google canonical CWE-787
7.8
2018-12-07 CVE-2017-14888 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can pass IEs to the host driver and if multiple append commands are received, then the integer variable that stores the length can overflow and the subsequent copy of the IE data may potentially lead to a heap buffer overflow.
local
low complexity
google CWE-119
7.8
2018-12-06 CVE-2018-9568 Incorrect Type Conversion or Cast vulnerability in multiple products
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion.
local
low complexity
google canonical redhat linux CWE-704
7.8
2018-12-06 CVE-2018-9567 Unspecified vulnerability in Google Android
On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despite using different signing keys.
local
low complexity
google
7.8
2018-12-06 CVE-2018-9565 Integer Overflow or Wraparound vulnerability in Google Android 9.0
In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow.
network
low complexity
google CWE-190
7.5
2018-12-06 CVE-2018-9562 Out-of-bounds Read vulnerability in Google Android 9.0
In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size.
network
low complexity
google CWE-125
7.5