Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2018-12-06 CVE-2018-9538 Out-of-bounds Read vulnerability in Google Android 8.1/9.0
In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds read of a function pointer due to an incorrect bounds check.
local
low complexity
google CWE-125
7.8
2018-11-30 CVE-2018-15835 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
Android 1.0 through 9.0 has Insecure Permissions.
network
low complexity
google CWE-732
7.5
2018-11-27 CVE-2018-5919 Use After Free vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a use after free issue in WLAN host driver can lead to device reboot.
local
low complexity
google CWE-416
7.8
2018-11-27 CVE-2018-5910 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a memory corruption can occur in kernel due to improper check in callers count parameter in display handlers.
local
low complexity
google CWE-119
7.8
2018-11-27 CVE-2018-5909 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overflow occur may occur in display handlers due to lack of checking in buffer size before copying into it and will lead to memory corruption.
local
low complexity
google CWE-119
7.8
2018-11-27 CVE-2018-5908 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible buffer overflow in display function due to lack of buffer length validation before copying.
local
low complexity
google CWE-119
7.8
2018-11-27 CVE-2018-5906 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible buffer overflow in debugfs module due to lack of check in size of input before copying into buffer.
local
low complexity
google CWE-119
7.8
2018-11-27 CVE-2018-5904 Use After Free vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while list traversal in LPM status driver for clean up, use after free vulnerability may occur.
local
low complexity
google CWE-416
7.8
2018-11-27 CVE-2018-5861 Incorrect Type Conversion or Cast vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, existing checks in place on partition size are incomplete and can lead to heap overwrite vulnerabilities while loading a secure application from the boot loader.
local
low complexity
google CWE-704
7.8
2018-11-27 CVE-2018-5856 Use After Free vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, due to a race condition, a Use After Free condition can occur in Audio.
local
low complexity
google CWE-416
7.8