Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-06 CVE-2018-9459 Path Traversal vulnerability in Google Android
In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal error.
network
low complexity
google CWE-22
8.8
2018-11-06 CVE-2018-9458 Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 8.0/8.1
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window.
local
low complexity
google CWE-1021
7.8
2018-11-06 CVE-2018-9455 Out-of-bounds Read vulnerability in Google Android
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check.
network
low complexity
google CWE-125
7.5
2018-11-06 CVE-2018-9450 Out-of-bounds Write vulnerability in Google Android
In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2018-11-06 CVE-2018-9448 Out-of-bounds Read vulnerability in Google Android 8.0/8.1
In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2018-11-06 CVE-2018-9436 Out-of-bounds Read vulnerability in Google Android
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
7.5
2018-11-06 CVE-2018-9427 Out-of-bounds Write vulnerability in Google Android 8.0/8.1
In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
7.8
2018-11-06 CVE-2018-9422 Use After Free vulnerability in multiple products
In get_futex_key of futex.c, there is a use-after-free due to improper locking.
local
low complexity
google debian CWE-416
7.8
2018-11-06 CVE-2018-9415 Double Free vulnerability in multiple products
In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking.
local
low complexity
google canonical CWE-415
7.8
2018-11-06 CVE-2018-9385 Out-of-bounds Write vulnerability in Google Android
In driver_override_store of bus.c, there is a possible out of bounds write due to an incorrect bounds check.
local
low complexity
google CWE-787
7.8