Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-18 CVE-2017-8265 Double Free vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free.
local
high complexity
google CWE-415
7.0
2017-08-18 CVE-2017-8263 Unspecified vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a kernel fault can occur when doing certain operations on a read-only virtual address in userspace.
local
low complexity
google
7.8
2017-08-18 CVE-2017-8262 Use After Free vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in some memory allocation and free functions, a race condition can potentially occur leading to a Use After Free condition.
local
high complexity
google CWE-416
7.0
2017-08-18 CVE-2017-8261 Unspecified vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a camera driver ioctl, a kernel overwrite can potentially occur.
local
low complexity
google
7.8
2017-08-18 CVE-2017-8260 Out-of-bounds Write vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and cause an out of bounds write later.
local
low complexity
google CWE-787
7.8
2017-08-18 CVE-2017-8257 Race Condition vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while another process still has the debug buffer in use.
local
low complexity
google CWE-362
7.8
2017-08-18 CVE-2017-8256 Out-of-bounds Read vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, array out of bounds access can occur if userspace sends more than 16 multicast addresses.
local
low complexity
google CWE-125
7.8
2017-08-18 CVE-2017-8255 Integer Overflow or Wraparound vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in boot.
local
low complexity
google CWE-190
7.8
2017-08-18 CVE-2017-8253 Allocation of Resources Without Limits or Throttling vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel memory can potentially be overwritten if an invalid master is sent from userspace.
local
low complexity
google CWE-770
7.8
2017-08-18 CVE-2016-10389 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.
local
low complexity
google CWE-119
7.8