Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-16 CVE-2017-15831 Integer Overflow or Wraparound vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function wma_ndp_end_indication_event_handler(), there is no input validation check on a event_info value coming from firmware, which can cause an integer overflow and then leads to potential heap overwrite.
local
low complexity
google CWE-190
7.8
2018-03-16 CVE-2017-15830 Improper Validation of Array Index vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper ch_list array index initialization in function sme_set_plm_request() causes potential buffer overflow.
local
low complexity
google CWE-129
7.8
2018-03-16 CVE-2017-14889 Improper Validation of Array Index vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to the lack of a range check on the array index into the WMI descriptor pool, arbitrary address execution may potentially occur in the process mgmt completion handler.
local
low complexity
google CWE-129
7.8
2018-03-16 CVE-2017-14887 Integer Overflow or Wraparound vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of messages of type eWNI_SME_MODIFY_ADDITIONAL_IES, an integer overflow leading to heap buffer overflow may potentially occur.
local
low complexity
google CWE-190
7.8
2018-03-16 CVE-2017-11082 Race Condition vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in a firmware loading routine, a buffer overflow could potentially occur if multiple user space threads try to update the WLAN firmware file through sysfs.
local
high complexity
google CWE-362
7.0
2018-03-16 CVE-2017-11074 Unspecified vulnerability in Google Android
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is an obsolete set/reset ssid hotlist API.
local
low complexity
google
7.8
2018-03-16 CVE-2018-1000133 Improper Privilege Management vulnerability in Secluded Trident 1.4.6
Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unprivileged user could gain system administrator permissions within the web portal..
network
high complexity
secluded CWE-269
7.5
2018-03-15 CVE-2018-5476 Out-of-bounds Write vulnerability in Deltaww Delta Industrial Automation Dopsoft
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.00.01 or prior.
local
low complexity
deltaww CWE-787
7.8
2018-03-15 CVE-2017-16751 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Deltaww Delta Industrial Automation Screen Editor 2.00.23.00
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior.
local
low complexity
deltaww CWE-119
7.8
2018-03-15 CVE-2017-16749 Use After Free vulnerability in Deltaww Delta Industrial Automation Screen Editor 2.00.23.00
A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior.
local
low complexity
deltaww CWE-416
7.8