Vulnerabilities > Google > Android > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-16 CVE-2016-5859 Permissions, Privileges, and Access Controls vulnerability in Google Android
In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a buffer overflow.
local
high complexity
google CWE-264
7.0
2017-08-16 CVE-2016-5853 Permissions, Privileges, and Access Controls vulnerability in Google Android
In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value.
local
high complexity
google CWE-264
7.0
2017-08-11 CVE-2017-8273 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android release from CAF using the Linux kernel, while processing fastboot boot command when verified boot feature is disabled, with length greater than boot image buffer, a buffer overflow can occur.
local
low complexity
google CWE-119
7.8
2017-08-11 CVE-2017-8271 Out-of-bounds Write vulnerability in Google Android
Out of bound memory write can happen in the MDSS Rotator driver in all Qualcomm products with Android releases from CAF using the Linux kernel by an unsanitized userspace-controlled parameter.
local
low complexity
google CWE-787
7.8
2017-08-11 CVE-2017-8264 Resource Exhaustion vulnerability in Google Android
A userspace process can cause a Denial of Service in the camera driver in all Qualcomm products with Android releases from CAF using the Linux kernel.
local
low complexity
google CWE-400
7.8
2017-08-11 CVE-2017-8259 Classic Buffer Overflow vulnerability in Google Android
In the service locator in all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow can occur as the variable set for determining the size of the buffer is not used to indicate the size of the buffer.
local
low complexity
google CWE-120
7.8
2017-08-09 CVE-2017-0750 Out-of-bounds Write vulnerability in Google Android
A elevation of privilege vulnerability in the Upstream Linux file system.
local
low complexity
google CWE-787
7.8
2017-08-09 CVE-2017-0749 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Upstream Linux linux kernel.
local
low complexity
google
7.8
2017-08-09 CVE-2017-0747 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Qualcomm proprietary component.
local
low complexity
google
7.8
2017-08-09 CVE-2017-0746 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Qualcomm ipa driver.
local
low complexity
google
7.8