Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2016-10231 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm sound codec driver.
local
low complexity
google CWE-264
7.8
2018-04-04 CVE-2015-9015 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in Qualcomm closed source components.
local
low complexity
google CWE-264
7.8
2018-04-04 CVE-2018-6874 Cross-Site Request Forgery (CSRF) vulnerability in Auth0 Auth0.Js
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
network
low complexity
auth0 CWE-352
8.8
2018-04-04 CVE-2018-0986 Out-of-bounds Write vulnerability in Microsoft products
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.
network
low complexity
microsoft CWE-787
8.8
2018-04-04 CVE-2017-13271 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver.
network
low complexity
google
7.3
2018-04-04 CVE-2017-13270 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver.
network
low complexity
google
7.3
2018-04-04 CVE-2017-13265 Unspecified vulnerability in Google Android
A elevation of privilege vulnerability in the Android system (OTA updates).
network
low complexity
google
7.3
2018-04-04 CVE-2017-13264 Unspecified vulnerability in Google Android
A other vulnerability in the Android media framework (Avcdec).
network
low complexity
google
7.5
2018-04-04 CVE-2017-13263 Unspecified vulnerability in Google Android 8.0/8.1
A elevation of privilege vulnerability in the Android framework.
network
low complexity
google
7.3
2018-04-04 CVE-2017-13261 Out-of-bounds Read vulnerability in Google Android
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
7.5