CVE-2017-0262
CVEs:CVE-2017-0262
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 12 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2017-0262
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.
CVEs:CVE-2017-0262
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-...
CVEs:CVE-2017-0262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| office | affected | microsoft | — | — |
CVEs:CVE-2017-0261
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-...
CVEs:CVE-2017-0261
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| office | affected | microsoft | — | — |
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.
CVEs:CVE-2017-0261
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
CVEs:CVE-2017-0222
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| internet_explorer | affected | microsoft | — | — |
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
CVEs:CVE-2017-0222
CVEs:CVE-2017-0222
CVEs:CVE-2017-0263
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CVEs:CVE-2017-0263
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a ...
CVEs:CVE-2017-0263
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1511 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1703 | affected | microsoft | — | — |
| windows_7 | affected | microsoft | — | — |
| windows_8.1 | affected | microsoft | — | — |
| windows_rt_8.1 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
Information Exposure in cordova-android
CVEs:CVE-2016-6799
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cordova-android | affected | npm | cordova-android | — |
Information Exposure in cordova-android
CVEs:CVE-2016-6799
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cordova-android | affected | npm | cordova-android | — |
Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, ...
CVEs:CVE-2016-6799
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cordova | affected | apache | — | — |
CVEs:CVE-2015-9004
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
CVEs:CVE-2015-9004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...
CVEs:CVE-2017-0331
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
CVEs:CVE-2017-0331
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
CVEs:CVE-2014-9940
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
CVEs:CVE-2014-9940
A remote code execution vulnerability in libmpeg2 in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote ...
CVEs:CVE-2017-0587
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0587
A remote code execution vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the p...
CVEs:CVE-2017-0588
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0588
CVEs:CVE-2017-0589
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...
CVEs:CVE-2017-0589
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0590
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote c...
CVEs:CVE-2017-0590
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote co...
CVEs:CVE-2017-0591
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0591
CVEs:CVE-2017-0592
A remote code execution vulnerability in FLACExtractor.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to...
CVEs:CVE-2017-0592
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5868
drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process.
CVEs:CVE-2016-5868
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Red Hat Security Advisory: CFME 5.8.0 security, bug, and enhancement update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ansible | affected | Red Hat:cloudforms_managementengine:5.8::el7 | ansible | — |
| ansible-tower-server | affected | Red Hat:cloudforms_managementengine:5.8::el7 | ansible-tower-server | — |
| ansible-tower-setup | affected | Red Hat:cloudforms_managementengine:5.8::el7 | ansible-tower-setup | — |
| bubblewrap | affected | Red Hat:cloudforms_managementengine:5.8::el7 | bubblewrap | — |
| bubblewrap-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | bubblewrap-debuginfo | — |
| cfme | affected | Red Hat:cloudforms_managementengine:5.8::el7 | cfme | — |
| cfme-appliance | affected | Red Hat:cloudforms_managementengine:5.8::el7 | cfme-appliance | — |
| cfme-appliance-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | cfme-appliance-debuginfo | — |
| cfme-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | cfme-debuginfo | — |
| cfme-gemset | affected | Red Hat:cloudforms_managementengine:5.8::el7 | cfme-gemset | — |
| erlang | affected | Red Hat:cloudforms_managementengine:5.8::el7 | erlang | — |
| erlang-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | erlang-debuginfo | — |
| freeipmi | affected | Red Hat:cloudforms_managementengine:5.8::el7 | freeipmi | — |
| freeipmi-bmc-watchdog | affected | Red Hat:cloudforms_managementengine:5.8::el7 | freeipmi-bmc-watchdog | — |
| freeipmi-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | freeipmi-debuginfo | — |
| freeipmi-devel | affected | Red Hat:cloudforms_managementengine:5.8::el7 | freeipmi-devel | — |
| freeipmi-ipmidetectd | affected | Red Hat:cloudforms_managementengine:5.8::el7 | freeipmi-ipmidetectd | — |
| freeipmi-ipmiseld | affected | Red Hat:cloudforms_managementengine:5.8::el7 | freeipmi-ipmiseld | — |
| google-compute-engine | affected | Red Hat:cloudforms_managementengine:5.8::el7 | google-compute-engine | — |
| google-config | affected | Red Hat:cloudforms_managementengine:5.8::el7 | google-config | — |
| libtomcrypt | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtomcrypt | — |
| libtomcrypt-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtomcrypt-debuginfo | — |
| libtomcrypt-devel | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtomcrypt-devel | — |
| libtomcrypt-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtomcrypt-doc | — |
| libtommath | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtommath | — |
| libtommath-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtommath-debuginfo | — |
| libtommath-devel | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtommath-devel | — |
| libtommath-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | libtommath-doc | — |
| nginx | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx | — |
| nginx-all-modules | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-all-modules | — |
| nginx-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-debuginfo | — |
| nginx-filesystem | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-filesystem | — |
| nginx-mod-http-geoip | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-mod-http-geoip | — |
| nginx-mod-http-image-filter | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-mod-http-image-filter | — |
| nginx-mod-http-perl | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-mod-http-perl | — |
| nginx-mod-http-xslt-filter | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-mod-http-xslt-filter | — |
| nginx-mod-mail | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-mod-mail | — |
| nginx-mod-stream | affected | Red Hat:cloudforms_managementengine:5.8::el7 | nginx-mod-stream | — |
| postgresql94 | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94 | — |
| postgresql94-contrib | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-contrib | — |
| postgresql94-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-debuginfo | — |
| postgresql94-devel | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-devel | — |
| postgresql94-docs | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-docs | — |
| postgresql94-libs | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-libs | — |
| postgresql94-plperl | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-plperl | — |
| postgresql94-plpython | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-plpython | — |
| postgresql94-pltcl | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-pltcl | — |
| postgresql94-server | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-server | — |
| postgresql94-test | affected | Red Hat:cloudforms_managementengine:5.8::el7 | postgresql94-test | — |
| prince | affected | Red Hat:cloudforms_managementengine:5.8::el7 | prince | — |
| python-crypto | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-crypto | — |
| python-crypto-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-crypto-debuginfo | — |
| python-ecdsa | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-ecdsa | — |
| python-httplib2 | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-httplib2 | — |
| python-keyczar | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-keyczar | — |
| python-meld3 | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-meld3 | — |
| python-meld3-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-meld3-debuginfo | — |
| python-paramiko | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-paramiko | — |
| python-paramiko-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-paramiko-doc | — |
| python-passlib | affected | Red Hat:cloudforms_managementengine:5.8::el7 | python-passlib | — |
| rabbitmq-server | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rabbitmq-server | — |
| rh-postgresql95-postgresql-pglogical | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-postgresql95-postgresql-pglogical | — |
| rh-postgresql95-postgresql-pglogical-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-postgresql95-postgresql-pglogical-debuginfo | — |
| rh-postgresql95-repmgr | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-postgresql95-repmgr | — |
| rh-postgresql95-repmgr-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-postgresql95-repmgr-debuginfo | — |
| rh-ruby23-rubygem-bcrypt | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-bcrypt | — |
| rh-ruby23-rubygem-bcrypt-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-bcrypt-debuginfo | — |
| rh-ruby23-rubygem-bcrypt-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-bcrypt-doc | — |
| rh-ruby23-rubygem-eventmachine | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-eventmachine | — |
| rh-ruby23-rubygem-eventmachine-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-eventmachine-debuginfo | — |
| rh-ruby23-rubygem-eventmachine-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-eventmachine-doc | — |
| rh-ruby23-rubygem-ffi | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-ffi | — |
| rh-ruby23-rubygem-ffi-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-ffi-debuginfo | — |
| rh-ruby23-rubygem-ffi-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-ffi-doc | — |
| rh-ruby23-rubygem-hamlit | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-hamlit | — |
| rh-ruby23-rubygem-hamlit-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-hamlit-debuginfo | — |
| rh-ruby23-rubygem-hamlit-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-hamlit-doc | — |
| rh-ruby23-rubygem-http_parser.rb | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-http_parser.rb | — |
| rh-ruby23-rubygem-http_parser.rb-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-http_parser.rb-debuginfo | — |
| rh-ruby23-rubygem-http_parser.rb-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-http_parser.rb-doc | — |
| rh-ruby23-rubygem-json | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-json | — |
| rh-ruby23-rubygem-json-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-json-debuginfo | — |
| rh-ruby23-rubygem-json-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-json-doc | — |
| rh-ruby23-rubygem-linux_block_device | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-linux_block_device | — |
| rh-ruby23-rubygem-linux_block_device-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-linux_block_device-debuginfo | — |
| rh-ruby23-rubygem-linux_block_device-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-linux_block_device-doc | — |
| rh-ruby23-rubygem-memory_buffer | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-memory_buffer | — |
| rh-ruby23-rubygem-memory_buffer-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-memory_buffer-debuginfo | — |
| rh-ruby23-rubygem-memory_buffer-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-memory_buffer-doc | — |
| rh-ruby23-rubygem-net_app_manageability | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-net_app_manageability | — |
| rh-ruby23-rubygem-net_app_manageability-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-net_app_manageability-debuginfo | — |
| rh-ruby23-rubygem-net_app_manageability-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-net_app_manageability-doc | — |
| rh-ruby23-rubygem-nio4r | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-nio4r | — |
| rh-ruby23-rubygem-nio4r-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-nio4r-debuginfo | — |
| rh-ruby23-rubygem-nio4r-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-nio4r-doc | — |
| rh-ruby23-rubygem-nokogiri | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-nokogiri | — |
| rh-ruby23-rubygem-nokogiri-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-nokogiri-debuginfo | — |
| rh-ruby23-rubygem-nokogiri-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-nokogiri-doc | — |
| rh-ruby23-rubygem-ovirt-engine-sdk4 | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-ovirt-engine-sdk4 | — |
| rh-ruby23-rubygem-ovirt-engine-sdk4-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-ovirt-engine-sdk4-debuginfo | — |
| rh-ruby23-rubygem-ovirt-engine-sdk4-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-ovirt-engine-sdk4-doc | — |
| rh-ruby23-rubygem-pg | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-pg | — |
| rh-ruby23-rubygem-pg-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-pg-debuginfo | — |
| rh-ruby23-rubygem-pg-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-pg-doc | — |
| rh-ruby23-rubygem-pkg-config | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-pkg-config | — |
| rh-ruby23-rubygem-pkg-config-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-pkg-config-doc | — |
| rh-ruby23-rubygem-puma | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-puma | — |
| rh-ruby23-rubygem-puma-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-puma-debuginfo | — |
| rh-ruby23-rubygem-puma-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-puma-doc | — |
| rh-ruby23-rubygem-redhat_access_cfme | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-redhat_access_cfme | — |
| rh-ruby23-rubygem-redhat_access_cfme-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-redhat_access_cfme-doc | — |
| rh-ruby23-rubygem-redhat_access_lib | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-redhat_access_lib | — |
| rh-ruby23-rubygem-rugged | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-rugged | — |
| rh-ruby23-rubygem-rugged-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-rugged-debuginfo | — |
| rh-ruby23-rubygem-rugged-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-rugged-doc | — |
| rh-ruby23-rubygem-thin | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-thin | — |
| rh-ruby23-rubygem-thin-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-thin-debuginfo | — |
| rh-ruby23-rubygem-thin-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-thin-doc | — |
| rh-ruby23-rubygem-unf_ext | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-unf_ext | — |
| rh-ruby23-rubygem-unf_ext-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-unf_ext-debuginfo | — |
| rh-ruby23-rubygem-unf_ext-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-unf_ext-doc | — |
| rh-ruby23-rubygem-websocket-driver | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-websocket-driver | — |
| rh-ruby23-rubygem-websocket-driver-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-websocket-driver-debuginfo | — |
| rh-ruby23-rubygem-websocket-driver-doc | affected | Red Hat:cloudforms_managementengine:5.8::el7 | rh-ruby23-rubygem-websocket-driver-doc | — |
| smem | affected | Red Hat:cloudforms_managementengine:5.8::el7 | smem | — |
| sshpass | affected | Red Hat:cloudforms_managementengine:5.8::el7 | sshpass | — |
| sshpass-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | sshpass-debuginfo | — |
| supervisor | affected | Red Hat:cloudforms_managementengine:5.8::el7 | supervisor | — |
| wmi | affected | Red Hat:cloudforms_managementengine:5.8::el7 | wmi | — |
| wmi-debuginfo | affected | Red Hat:cloudforms_managementengine:5.8::el7 | wmi-debuginfo | — |
Red Hat Security Advisory: chromium-browser security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser | affected | Red Hat:rhel_extras:6 | chromium-browser | — |
| chromium-browser-debuginfo | affected | Red Hat:rhel_extras:6 | chromium-browser-debuginfo | — |
Security update for Chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 12 SP2 | chromium | — |
Security update for Chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 12 SP2 | chromium | — |
CVEs:CVE-2017-5068
Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
CVEs:CVE-2017-5068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
Integer overflow in soundtrigger/ISoundTriggerHwService.cpp in Android allows attacks to cause a denial of service via unspecified vectors.
CVEs:CVE-2015-1529
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2015-1529
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior ...
CVEs:CVE-2017-2171
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| captcha | affected | bestwebsoft | — | — |
| car_rental | affected | bestwebsoft | — | — |
| contact_form | affected | bestwebsoft | — | — |
| contact_form_multi | affected | bestwebsoft | — | — |
| contact_form_to_db | affected | bestwebsoft | — | — |
| custom_admin_page | affected | bestwebsoft | — | — |
| custom_fields_search | affected | bestwebsoft | — | — |
| custom_search | affected | bestwebsoft | — | — |
| donate | affected | bestwebsoft | — | — |
| email_queue | affected | bestwebsoft | — | — |
| error_log_viewer | affected | bestwebsoft | — | — |
| facebook_button | affected | bestwebsoft | — | — |
| featured_posts | affected | bestwebsoft | — | — |
| gallery | affected | bestwebsoft | — | — |
| gallery_categories | affected | bestwebsoft | — | — |
| google_\+1 | affected | bestwebsoft | — | — |
| google_adsense | affected | bestwebsoft | — | — |
| google_analytics | affected | bestwebsoft | — | — |
| google_captcha_\(recaptcha\) | affected | bestwebsoft | — | — |
| google_maps | affected | bestwebsoft | — | — |
| google_shortlink | affected | bestwebsoft | — | — |
| google_sitemap | affected | bestwebsoft | — | — |
| htaccess | affected | bestwebsoft | — | — |
| job_board | affected | bestwebsoft | — | — |
| latest_posts | affected | bestwebsoft | — | — |
| limit_attempts | affected | bestwebsoft | — | — |
| affected | bestwebsoft | — | — | |
| multilanguage | affected | bestwebsoft | — | — |
| pagination | affected | bestwebsoft | — | — |
| pdf_\&_print | affected | bestwebsoft | — | — |
| affected | bestwebsoft | — | — | |
| popular_posts | affected | bestwebsoft | — | — |
| portfolio | affected | bestwebsoft | — | — |
| post_to_csv | affected | bestwebsoft | — | — |
| profile_extra | affected | bestwebsoft | — | — |
| promobar | affected | bestwebsoft | — | — |
| quotes_and_tips | affected | bestwebsoft | — | — |
| realty | affected | bestwebsoft | — | — |
| re-attacher | affected | bestwebsoft | — | — |
| relevant_-_related_posts | affected | bestwebsoft | — | — |
| sender | affected | bestwebsoft | — | — |
| smtp | affected | bestwebsoft | — | — |
| social_buttons_pack | affected | bestwebsoft | — | — |
| subscriber | affected | bestwebsoft | — | — |
| testimonials | affected | bestwebsoft | — | — |
| timesheet | affected | bestwebsoft | — | — |
| twitter_button | affected | bestwebsoft | — | — |
| updater | affected | bestwebsoft | — | — |
| user_role | affected | bestwebsoft | — | — |
| visitors_online | affected | bestwebsoft | — | — |
| zendesk_help_center | affected | bestwebsoft | — | — |
CVEs:CVE-2017-2171
CVEs:CVE-2017-0594
An elevation of privilege vulnerability in codecs/aacenc/SoftAACEncoder2.cpp in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High b...
CVEs:CVE-2017-0594
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local...
CVEs:CVE-2017-0595
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0595
CVEs:CVE-2017-0596
An elevation of privilege vulnerability in libstagefright in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local...
CVEs:CVE-2017-0596
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for ...
CVEs:CVE-2016-5853
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5853
CVEs:CVE-2017-0597
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevate...
CVEs:CVE-2017-0597
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10239
In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer ...
CVEs:CVE-2016-10239
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Produ...
CVEs:CVE-2017-0599
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0599
An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromis...
CVEs:CVE-2017-0620
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
CVEs:CVE-2017-0620
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...
CVEs:CVE-2016-10275
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10275
An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...
CVEs:CVE-2017-0465
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
CVEs:CVE-2017-0465
In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.
CVEs:CVE-2016-10238
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10238
In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a buffer overflow.
CVEs:CVE-2016-5859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5859
CVEs:CVE-2016-5860
In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a heap buffer overflow.
CVEs:CVE-2016-5860
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10276
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device...
CVEs:CVE-2016-10276
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases from CAF using the Linux kernel, the TA would not detect an issue and it would be treated as secure mem...
CVEs:CVE-2016-10237
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10237
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanen...
CVEs:CVE-2016-10274
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10274
CVEs:CVE-2017-0604
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permane...
CVEs:CVE-2017-0604
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.
CVEs:CVE-2016-5867
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5867
An elevation of privilege vulnerability in the MediaTek power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged ...
CVEs:CVE-2017-0615
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0615
CVEs:CVE-2017-0616
An elevation of privilege vulnerability in the MediaTek system management interrupt driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires comp...
CVEs:CVE-2017-0616
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An elevation of privilege vulnerability in the MediaTek video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged ...
CVEs:CVE-2017-0617
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0617
CVEs:CVE-2017-0619
An elevation of privilege vulnerability in the Qualcomm pin controller driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pr...
CVEs:CVE-2017-0619
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| linux_kernel | affected | linux | — | — |
In the Secure File System in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.
CVEs:CVE-2014-9944
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9944
CVEs:CVE-2015-9005
In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.
CVEs:CVE-2015-9005
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5347
In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to userspace by an audio driver.
CVEs:CVE-2016-5347
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.
CVEs:CVE-2016-5858
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5858
CVEs:CVE-2016-10280
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...
CVEs:CVE-2016-10280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10281
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...
CVEs:CVE-2016-10281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10282
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege...
CVEs:CVE-2016-10282
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0618
An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pri...
CVEs:CVE-2017-0618
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5862
When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a ...
CVEs:CVE-2016-5862
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
CVEs:CVE-2014-9945
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9945
In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.
CVEs:CVE-2014-9943
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9943
CVEs:CVE-2014-9923
In NAS in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.
CVEs:CVE-2014-9923
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9924
In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.
CVEs:CVE-2014-9924
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In HDR in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.
CVEs:CVE-2014-9925
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9925
CVEs:CVE-2014-9926
In GNSS in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.
CVEs:CVE-2014-9926
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9928
In GERAN in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.
CVEs:CVE-2014-9928
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In WCDMA in all Android releases from CAF using the Linux kernel, a Use of Out-of-range Pointer Offset vulnerability could potentially exist.
CVEs:CVE-2014-9929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9929
CVEs:CVE-2014-9930
In WCDMA in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.
CVEs:CVE-2014-9930
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Boot in all Android releases from CAF using the Linux kernel, a Use of Uninitialized Variable vulnerability could potentially exist.
CVEs:CVE-2014-9942
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9942
In Core Kernel in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.
CVEs:CVE-2014-9946
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9946
CVEs:CVE-2014-9948
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Validation of Array Index vulnerability could potentially exist.
CVEs:CVE-2014-9948
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9949
In TrustZone in all Android releases from CAF using the Linux kernel, an Untrusted Pointer Dereference vulnerability could potentially exist.
CVEs:CVE-2014-9949
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2015-9007
In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.
CVEs:CVE-2015-9007
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9950
In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
CVEs:CVE-2014-9950
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9952
In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist.
CVEs:CVE-2014-9952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially exist.
CVEs:CVE-2015-9006
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2015-9006
CVEs:CVE-2017-0603
A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product:...
CVEs:CVE-2017-0603
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspace.
CVEs:CVE-2016-5854
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5854
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is casted to a structure without checking if the source buffer is large enough.
CVEs:CVE-2016-5855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5855
CVEs:CVE-2017-0593
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This issue is rated as High because it is a general bypass for operating system protections that isolate ap...
CVEs:CVE-2017-0593
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0635
A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Low due to details specific to the vulnerabilit...
CVEs:CVE-2017-0635
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A remote denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service...
CVEs:CVE-2017-0600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0600
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.
CVEs:CVE-2014-9947
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9947
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.
CVEs:CVE-2014-9951
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-9951
CVEs:CVE-2014-9927
In UIM in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.
CVEs:CVE-2014-9927
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0598
An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used ...
CVEs:CVE-2017-0598
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0602
An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the ...
CVEs:CVE-2017-0602
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-10242
A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the Linux kernel.
CVEs:CVE-2016-10242
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction re...
CVEs:CVE-2017-0601
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0601
CVEs:CVE-2014-9941
In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.
CVEs:CVE-2014-9941
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
An information disclosure vulnerability in the MediaTek command queue driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data witho...
CVEs:CVE-2017-0625
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0625
An information disclosure vulnerability in File-Based Encryption could enable a local malicious attacker to bypass operating system protections for the lock screen. This issue is rated as Moderate due to the possibility of bypassing the lock screen. Pr...
CVEs:CVE-2017-0493
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-0493
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_...
CVEs:CVE-2017-9045
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_i\/o_2017 | affected | — | — |
CVEs:CVE-2017-9045
CVEs:CVE-2017-8245
In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by specifying a payload size that will overflow its own declared size, an out of bounds memory copy occurs.
CVEs:CVE-2017-8245
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In function msm_pcm_playback_close() in all Android releases from CAF using the Linux kernel, prtd is assigned substream->runtime->private_data. Later, prtd is freed. However, prtd is not sanitized and set to NULL, resulting in a dangling pointer. Ther...
CVEs:CVE-2017-8246
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-8246
CVEs:CVE-2017-8244
In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_buf->curr" and "dbg_buf->filled_size" could be modified by different threads at the same time, but they are not protected with mutex ...
CVEs:CVE-2017-8244
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.