Vulnerabilities > Google > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-11-14 CVE-2018-9544 Out-of-bounds Read vulnerability in Google Android 9.0
In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2018-11-14 CVE-2018-9543 Information Exposure vulnerability in Google Android
In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset.
local
low complexity
google CWE-200
5.5
2018-11-14 CVE-2018-9457 Missing Authorization vulnerability in Google Android 8.0/8.1/9.0
In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass.
local
low complexity
google CWE-862
5.5
2018-11-14 CVE-2018-9347 Improper Input Validation vulnerability in Google Android
In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop.
network
low complexity
google CWE-20
6.5
2018-11-06 CVE-2018-9454 Out-of-bounds Read vulnerability in Google Android
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2018-11-06 CVE-2018-9453 Out-of-bounds Read vulnerability in Google Android
In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2018-11-06 CVE-2018-9451 Out-of-bounds Read vulnerability in Google Android
In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.5
2018-11-06 CVE-2018-9445 Path Traversal vulnerability in Google Android
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy.
low complexity
google CWE-22
6.8
2018-11-06 CVE-2018-9444 Infinite Loop vulnerability in Google Android
In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop.
local
low complexity
google CWE-835
5.5
2018-11-06 CVE-2018-9438 Unspecified vulnerability in Google Android 8.1
When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks.
local
low complexity
google
5.0