Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-06-12 CVE-2018-5847 Use After Free vulnerability in Google Android
Early or late retirement of rotation requests can result in a Use After Free condition in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-416
7.8
2018-06-12 CVE-2018-5844 Use After Free vulnerability in Google Android
In the video driver function set_output_buffers(), binfo can be accessed after being freed in a failure scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-416
7.8
2018-06-12 CVE-2018-5843 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, there is no upper bound check on the value event->num_chains_valid received from firmware which can lead to a buffer overwrite of the fixed size chain_rssi_result structure.
local
low complexity
google CWE-119
7.8
2018-06-12 CVE-2018-5842 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
An arbitrary address write can occur if a compromised WLAN firmware sends incorrect data to WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-119
7.8
2018-06-12 CVE-2018-3582 Improper Input Validation vulnerability in Google Android
Buffer overflow can occur due to improper input validation in multiple WMA event handler functions in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-20
7.8
2018-06-12 CVE-2018-3581 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overwrite can occur if the vdev_id received from firmware is larger than max_bssid.
local
low complexity
google CWE-119
7.8
2018-06-12 CVE-2018-3576 Improper Validation of Array Index vulnerability in Google Android
improper validation of array index in WiFi driver function sapInterferenceRssiCount() leads to array out-of-bounds access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-129
7.8
2018-06-12 CVE-2018-3572 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
While processing a DSP buffer in an audio driver's event handler, an index of a buffer is not checked before accessing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
local
low complexity
google CWE-119
7.8
2018-06-12 CVE-2018-3571 Use After Free vulnerability in Google Android
In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations
local
low complexity
google CWE-416
7.8
2018-06-12 CVE-2018-0496 Path Traversal vulnerability in multiple products
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.
network
low complexity
dinknetwork debian CWE-22
7.5