Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-27 CVE-2018-11995 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a partition name-check variable is not reset for every iteration which may cause improper termination in the META image.
local
low complexity
google CWE-119
7.8
2018-11-27 CVE-2018-11956 Unspecified vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper mounting lead to device node and executable to be run from /dsp/ which presents a potential security issue.
local
low complexity
google
7.8
2018-11-27 CVE-2018-11943 Improper Initialization vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing fastboot flash command, memory leak or unexpected behavior may occur due to processing of unintialized data buffers.
local
low complexity
google CWE-665
7.8
2018-11-27 CVE-2018-11919 Out-of-bounds Write vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a potential heap overflow and memory corruption due to improper error handling in SOC infrastructure.
local
low complexity
google CWE-787
7.8
2018-11-27 CVE-2018-11918 Double Free vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated is automatically released by the kernel if the 'probe' function fails with an error code.
local
low complexity
google CWE-415
7.8
2018-11-27 CVE-2018-11914 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /systemrw/ which presents a potential security.
local
low complexity
google CWE-732
7.8
2018-11-27 CVE-2018-11913 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of dev nodes may lead to potential security issue.
local
low complexity
google CWE-732
7.8
2018-11-27 CVE-2018-11912 Improper Privilege Management vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of daemons may lead to unprivileged access.
local
low complexity
google CWE-269
7.8
2018-11-27 CVE-2018-11911 Improper Privilege Management vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of script may lead to unprivileged access.
local
low complexity
google CWE-269
7.8
2018-11-27 CVE-2018-11910 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /persist/ which presents a potential issue.
local
low complexity
google CWE-732
7.8