Vulnerabilities > Google > High

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-11073 Unspecified vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the qcacld pktlog allows mapping memory via /proc/ath_pktlog/cld to user space.
local
low complexity
google
7.8
2017-11-16 CVE-2017-11058 Out-of-bounds Read vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.
network
low complexity
google CWE-125
7.5
2017-11-16 CVE-2017-11038 Unspecified vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing the boot image header, range checks can be bypassed by supplying different versions of the header at the time of check and use.
local
low complexity
google
7.8
2017-11-16 CVE-2017-11035 Out-of-bounds Read vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, possible buffer overflow or information leak in the functions "sme_set_ft_ies" and "csr_roam_issue_ft_preauth_req" due to incorrect initialization of WEXT callbacks and lack of the checks for buffer size.
local
low complexity
google CWE-125
7.8
2017-11-16 CVE-2017-11032 Double Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a double free can occur when kmalloc fails to allocate memory for pointers resp/req in the service-locator driver function service_locator_send_msg().
local
low complexity
google CWE-415
7.8
2017-11-16 CVE-2017-11029 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer, which resides in user space.
local
low complexity
google CWE-119
7.8
2017-11-16 CVE-2017-11028 Information Exposure vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the ISP Camera driver, the contents of an arbitrary kernel address can be leaked to userspace by the function msm_isp_get_stream_common_data().
network
low complexity
google CWE-200
7.5
2017-11-16 CVE-2017-11027 Improper Input Validation vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not validated for being smaller than minimum header size causing unintialized data access vulnerability.
local
low complexity
google CWE-20
7.8
2017-11-16 CVE-2017-11026 Use of Hard-coded Credentials vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing FRP partition using reference FRP unlock, authentication method can be compromised for static keys.
local
low complexity
google CWE-798
7.8
2017-11-16 CVE-2017-11025 Race Condition vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in the function audio_effects_shared_ioctl(), memory corruption can occur.
local
high complexity
google CWE-362
7.0