Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2017-13287 Improper Input Validation vulnerability in Google Android
In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation.
local
low complexity
google CWE-20
7.8
2018-04-04 CVE-2017-13286 Deserialization of Untrusted Data vulnerability in Google Android 8.0/8.1
In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization.
local
low complexity
google CWE-502
7.8
2018-04-04 CVE-2017-13285 Out-of-bounds Write vulnerability in Google Android
In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitialized buffer.
network
low complexity
google CWE-787
critical
9.8
2018-04-04 CVE-2017-13284 Improper Input Validation vulnerability in Google Android
In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation.
network
low complexity
google CWE-20
critical
9.8
2018-04-04 CVE-2017-13283 Out-of-bounds Write vulnerability in Google Android
In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a missing bounds check.
network
low complexity
google CWE-787
critical
9.8
2018-04-04 CVE-2017-13282 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check.
network
low complexity
google CWE-119
critical
9.8
2018-04-04 CVE-2017-13281 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 8.0/8.1
In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible stack buffer overflow due to an incorrect bounds check.
network
low complexity
google CWE-119
critical
9.8
2018-04-04 CVE-2017-13280 Out-of-bounds Read vulnerability in Google Android
In the FrameSequence_gif::FrameSequence_gif function of libframesequence, there is a out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2018-04-04 CVE-2017-13279 Excessive Iteration vulnerability in Google Android
In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of pushing items into a vector.
local
low complexity
google CWE-834
5.5
2018-04-04 CVE-2017-13278 Use After Free vulnerability in Google Android
In MediaPlayerService::Client::notify of MediaPlayerService.cpp, there is a possible use after free.
local
low complexity
google CWE-416
7.8