Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-11-19 CVE-2018-9440 Unspecified vulnerability in Google Android
In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation.
network
low complexity
google
6.5
2024-11-19 CVE-2018-9412 Unspecified vulnerability in Google Android
In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation.
local
low complexity
google
5.5
2024-11-19 CVE-2018-9420 Use of Uninitialized Resource vulnerability in Google Android
In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized data.
local
low complexity
google CWE-908
5.5
2024-11-19 CVE-2018-9421 Use of Uninitialized Resource vulnerability in Google Android
In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data.
local
low complexity
google CWE-908
5.5
2024-11-19 CVE-2018-9410 Out-of-bounds Read vulnerability in Google Android 8.0/8.1
In analyzeAxes of FontUtils.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2024-11-19 CVE-2018-9348 Integer Overflow or Wraparound vulnerability in Google Android
In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow.
network
low complexity
google CWE-190
6.5
2024-11-19 CVE-2018-9371 Out-of-bounds Write vulnerability in Google Android
In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting.
low complexity
google CWE-787
6.4
2024-11-19 CVE-2018-9340 Out-of-bounds Read vulnerability in Google Android
In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.
local
low complexity
google CWE-125
5.5
2024-11-19 CVE-2018-9345 Use of Uninitialized Resource vulnerability in Google Android
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data.
local
low complexity
google CWE-908
5.5
2024-11-19 CVE-2018-9346 Use of Uninitialized Resource vulnerability in Google Android
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data.
local
low complexity
google CWE-908
5.5