Vulnerabilities > Google > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-02-19 CVE-2017-7376 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
network
low complexity
xmlsoft google debian CWE-119
critical
10.0
2018-02-12 CVE-2017-13230 Out-of-bounds Write vulnerability in Google Android
In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value.
network
google CWE-787
critical
9.3
2018-02-12 CVE-2017-13229 Improper Input Validation vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (n/a).
network
low complexity
google CWE-20
critical
10.0
2018-02-12 CVE-2017-13228 Out-of-bounds Write vulnerability in Google Android
In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character.
network
google CWE-787
critical
9.3
2018-01-12 CVE-2017-13225 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In libMtkOmxVdec.so there is a possible heap buffer overflow.
network
google CWE-119
critical
9.3
2018-01-12 CVE-2017-13208 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response.
network
low complexity
google CWE-119
critical
10.0
2018-01-12 CVE-2017-13179 Use After Free vulnerability in Google Android
In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free.
network
low complexity
google CWE-416
critical
10.0
2018-01-12 CVE-2017-13178 Use After Free vulnerability in Google Android
In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails.
network
low complexity
google CWE-416
critical
10.0
2018-01-12 CVE-2017-13177 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In several functions of libhevc, NEON registers are not preserved.
network
low complexity
google CWE-119
critical
10.0
2018-01-12 CVE-2017-13176 Improper Input Validation vulnerability in Google Android
In the parseURL function of URLStreamHandler, there is improper input validation of the host field.
network
google CWE-20
critical
9.3