Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2018-02-23 CVE-2017-15817 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.
network
google CWE-20
critical
9.3
2018-02-23 CVE-2017-14884 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the function WLANQCMBR_McProcessMsg, a buffer overflow may potentially occur in WLANFTM_McProcessMsg.
local
low complexity
google CWE-119
7.2
2018-02-19 CVE-2017-7376 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
network
low complexity
xmlsoft google debian CWE-119
critical
10.0
2018-02-19 CVE-2017-7375 XXE vulnerability in multiple products
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes).
network
low complexity
xmlsoft debian google CWE-611
7.5
2018-02-15 CVE-2017-13273 Unspecified vulnerability in Google Android
In xt_qtaguid.c, there is a race condition due to insufficient locking.
local
google
6.9
2018-02-12 CVE-2017-13247 Missing Authorization vulnerability in Google Android
In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock.
local
low complexity
google CWE-862
4.6
2018-02-12 CVE-2017-13246 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Upstream kernel network driver.
network
low complexity
google CWE-200
5.0
2018-02-12 CVE-2017-13245 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Upstream kernel audio driver.
local
low complexity
google
4.6
2018-02-12 CVE-2017-13244 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Upstream kernel easel.
local
low complexity
google
4.6
2018-02-12 CVE-2017-13243 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android system (ui).
network
low complexity
google CWE-200
5.0