Google Security Advisories · March 2008 — Google Security Advisories
2 advisories 2 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2008-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-0986

Open SourceActive exploitation (sightings)CRITICAL2008-03-06

Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field.

CVEs:CVE-2008-0986

Affected products

ProductStatusVendorPackageEcosystem
android_sdk affected google
Upstream advisory

CVE-2008-0985

Open SourceActive exploitation (sightings)CRITICAL2008-03-06

Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute arbitrary code via a crafted GIF file whose logical screen height and width are different than the actu...

CVEs:CVE-2008-0985

Affected products

ProductStatusVendorPackageEcosystem
android_sdk affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.