Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2017-13307 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Upstream kernel pci sysfs.
network
low complexity
google
7.5
2018-04-04 CVE-2017-13306 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Upstream kernel mnh driver.
network
low complexity
google
7.5
2018-04-04 CVE-2017-13302 Improper Input Validation vulnerability in Google Android 8.0
A denial of service vulnerability in the Android system (system ui).
network
low complexity
google CWE-20
7.8
2018-04-04 CVE-2017-13301 Improper Input Validation vulnerability in Google Android 8.0
A denial of service vulnerability in the Android system (system ui).
network
low complexity
google CWE-20
7.8
2018-04-04 CVE-2017-13293 Out-of-bounds Write vulnerability in Google Android
In the nfc_hci_cmd_received() function of core.c, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google CWE-787
7.2
2018-04-04 CVE-2017-13291 NULL Pointer Dereference vulnerability in Google Android
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible NULL pointer dereference due to missing bounds checks.
network
low complexity
google CWE-476
7.8
2018-04-04 CVE-2017-13289 Incorrect Calculation of Buffer Size vulnerability in Google Android
In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size mismatch.
local
low complexity
google CWE-131
7.2
2018-04-04 CVE-2017-13288 Incorrect Calculation vulnerability in Google Android 8.0/8.1
In writeToParcel and readFromParcel of PeriodicAdvertisingReport.java, there is a permission bypass due to a 64/32bit int mismatch.
local
low complexity
google CWE-682
7.2
2018-04-04 CVE-2017-13287 Improper Input Validation vulnerability in Google Android
In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation.
local
low complexity
google CWE-20
7.2
2018-04-04 CVE-2017-13286 Deserialization of Untrusted Data vulnerability in Google Android 8.0/8.1
In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization.
local
low complexity
google CWE-502
7.2