Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2017-13277 Out-of-bounds Write vulnerability in Google Android
In ihevcd_fmt_conv of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.8
2018-04-04 CVE-2017-13276 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In CProgramConfig_ReadHeightExt of tpdec_asc.cpp, there is a possible stack buffer overflow due to a missing bounds check.
local
low complexity
google CWE-119
7.8
2018-04-04 CVE-2017-13275 Out-of-bounds Read vulnerability in Google Android 8.0/8.1
In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bounds check.
local
low complexity
google CWE-125
5.5
2018-04-04 CVE-2017-13274 Origin Validation Error vulnerability in Google Android
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination.
network
low complexity
google CWE-346
critical
9.8
2018-04-04 CVE-2017-13267 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check.
network
low complexity
google CWE-119
critical
9.8
2018-04-03 CVE-2018-5828 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_extscan_start_stop_event_handler(), vdev_id comes from the variable event from firmware and is not properly validated potentially leading to a buffer overwrite.
local
low complexity
google CWE-119
7.8
2018-04-03 CVE-2018-5826 Use After Free vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, due to a race condition, a Use After Free condition can occur in the WLAN driver.
network
high complexity
google CWE-416
5.9
2018-04-03 CVE-2018-5825 Use After Free vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the kernel IPA driver, a Use After Free condition can occur.
local
low complexity
google CWE-416
7.8
2018-04-03 CVE-2018-5824 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing HTT_T2H_MSG_TYPE_RX_FLUSH or HTT_T2H_MSG_TYPE_RX_PN_IND messages, a buffer overflow can occur if the tid value obtained from the firmware is out of range.
local
low complexity
google CWE-119
7.8
2018-04-03 CVE-2018-5823 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, improper buffer length validation in extscan hotlist event can lead to potential buffer overflow.
local
low complexity
google CWE-119
7.8