Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2017-13184 Use After Free vulnerability in Google Android 8.0/8.1
In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyncInjector.
local
low complexity
google CWE-416
7.8
2018-01-12 CVE-2017-13183 Race Condition vulnerability in Google Android 8.1
In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free due to a race condition if the user frees the buffer while it's being used in another thread.
local
high complexity
google CWE-362
7.0
2018-01-12 CVE-2017-13182 Integer Overflow or Wraparound vulnerability in Google Android 8.0/8.1
In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write.
local
low complexity
google CWE-190
7.8
2018-01-12 CVE-2017-13181 Double Free vulnerability in Google Android
In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer.
local
low complexity
google CWE-415
7.8
2018-01-12 CVE-2017-13180 Use After Free vulnerability in Google Android
In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing.
local
low complexity
google CWE-416
7.8
2018-01-12 CVE-2017-13176 Improper Input Validation vulnerability in Google Android
In the parseURL function of URLStreamHandler, there is improper input validation of the host field.
network
low complexity
google CWE-20
8.8
2018-01-12 CVE-2017-0855 Missing Release of Resource after Effective Lifetime vulnerability in Google Android
In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks.
network
low complexity
google CWE-772
7.5
2018-01-12 CVE-2017-0846 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android framework (clipboardservice).
network
low complexity
google CWE-200
7.5
2018-01-12 CVE-2015-9250 Path Traversal vulnerability in Skyboxsecurity Skybox Platform
An issue was discovered in Skybox Platform before 7.5.201.
network
low complexity
skyboxsecurity CWE-22
7.5
2018-01-12 CVE-2017-16739 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in We-Con Levistudio HMI Editor Firmware 1.8.29
An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior.
local
low complexity
we-con CWE-119
7.8