Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-06 CVE-2018-5862 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In __wlan_hdd_cfg80211_vendor_scan() in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, when SCAN_SSIDS and QCA_WLAN_VENDOR_ATTR_SCAN_FREQUENCIES are parsed, a buffer overwrite can potentially occur.
local
low complexity
google CWE-119
7.8
2018-07-06 CVE-2018-5859 Use After Free vulnerability in Google Android
Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a Use After Free condition can occur.
local
high complexity
google CWE-416
7.0
2018-07-06 CVE-2018-5858 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In the audio debugfs in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, out of bounds access can occur.
local
low complexity
google CWE-119
7.8
2018-07-06 CVE-2018-5853 Use After Free vulnerability in Google Android
A race condition exists in a driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-05-05 potentially leading to a use-after-free condition.
local
high complexity
google CWE-416
7.0
2018-07-06 CVE-2018-3587 Use After Free vulnerability in Google Android
In a firmware memory dump feature in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android), a Use After Free condition can occur.
local
low complexity
google CWE-416
7.8
2018-07-06 CVE-2018-3570 NULL Pointer Dereference vulnerability in Google Android
In the cpuidle driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, the list_for_each macro was not used correctly which could lead to an untrusted pointer dereference.
local
low complexity
google CWE-476
7.8
2018-07-06 CVE-2018-11304 Integer Overflow or Wraparound vulnerability in Google Android
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
local
low complexity
google CWE-190
7.8
2018-07-06 CVE-2017-15851 Information Exposure vulnerability in Google Android
Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera crash in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel
local
low complexity
google CWE-200
7.8
2018-07-06 CVE-2018-5899 Use After Free vulnerability in Google Android
In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, whenever TDLS connection is setup, we are freeing the netbuf in ol_tx_completion_handler and after that, we are accessing it in NBUF_UPDATE_TX_PKT_COUNT causing a use after free.
local
low complexity
google CWE-416
7.8
2018-07-06 CVE-2018-5898 Integer Overflow or Wraparound vulnerability in Google Android
Integer overflow can occur in msm_pcm_adsp_stream_cmd_put() function if the user supplied data "param_length" goes beyond certain limit in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.
local
low complexity
google CWE-190
7.8