Google Security Advisories · July 2017 — Google Security Advisories
302 advisories 153 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2017-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

RHSA-2017:1833

Open SourceEPSS <= 49%HIGH2017-07-31

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

openSUSE-SU-2017:1993-1

Open SourceEPSS <= 49%CRITICAL2017-07-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2017:1994-1

Open SourceEPSS <= 49%CRITICAL2017-07-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

CVE-2017-5098

GoogleEPSS <= 49%CRITICAL2017-07-26

A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5098

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-7000

Open SourceEPSS <= 49%CRITICAL2017-07-26

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory cor...

CVEs:CVE-2017-7000

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chromium
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

DEBIAN-CVE-2017-1000056

Open SourceEPSS <= 49%CRITICAL2017-07-17

DEBIAN-CVE-2017-1000056

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2017-1000056

Open SourceEPSS <= 49%CRITICAL2017-07-13

Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.

CVEs:CVE-2017-1000056

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

SUSE-RU-2017:1965-1

Open SourceEPSS <= 49%HIGH2017-07-12

Recommended update for Docker, RunC, Containerd

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:OpenStack Cloud 6 containerd
containerd affected SUSE:Linux Enterprise Module for Containers 12 containerd
docker affected SUSE:Linux Enterprise Module for Containers 12 docker
docker affected SUSE:OpenStack Cloud 6 docker
docker-distribution affected SUSE:Linux Enterprise Module for Containers 12 docker-distribution
golang-github-docker-libnetwork affected SUSE:OpenStack Cloud 6 golang-github-docker-libnetwork
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 12 golang-github-docker-libnetwork
runc affected SUSE:Linux Enterprise Module for Containers 12 runc
runc affected SUSE:OpenStack Cloud 6 runc
Upstream advisory

CVE-2017-5102

GoogleEPSS <= 49%HIGH2017-07-26

Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2017-5102

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5103

GoogleEPSS <= 49%HIGH2017-07-26

Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2017-5103

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5091

GoogleEPSS <= 49%CRITICAL2017-07-26

A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5091

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5097

GoogleEPSS <= 49%HIGH2017-07-26

Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5097

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5107

GoogleEPSS <= 49%MEDIUM2017-07-26

A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.

CVEs:CVE-2017-5107

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0678

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

CVEs:CVE-2017-0678

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0700

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.

CVEs:CVE-2017-0700

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5095

GoogleEPSS <= 49%CRITICAL2017-07-26

Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.

CVEs:CVE-2017-5095

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5094

GoogleEPSS <= 49%MEDIUM2017-07-26

Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted HTML page.

CVEs:CVE-2017-5094

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5108

GoogleEPSS <= 49%HIGH2017-07-26

Type confusion in PDFium in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted PDF file.

CVEs:CVE-2017-5108

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5099

GoogleEPSS <= 49%HIGH2017-07-26

Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page.

CVEs:CVE-2017-5099

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5093

GoogleEPSS <= 49%MEDIUM2017-07-26

Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to prevent a full screen warning from being displayed via a crafted HTML page.

CVEs:CVE-2017-5093

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5104

GoogleEPSS <= 49%MEDIUM2017-07-26

Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.

CVEs:CVE-2017-5104

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5092

GoogleEPSS <= 49%HIGH2017-07-26

Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2017-5092

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-0340

Open SourceEPSS <= 49%HIGH2017-07-06

An elevation of privilege vulnerability in the NVIDIA Libnvparser component due to a memcpy into a fixed sized buffer with a user-controlled size could lead to a memory corruption and possible remote code execution. This issue is rated as High. Product...

CVEs:CVE-2017-0340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5101

GoogleEPSS <= 49%MEDIUM2017-07-26

Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.

CVEs:CVE-2017-5101

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5110

GoogleEPSS <= 49%MEDIUM2017-07-26

Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTM...

CVEs:CVE-2017-5110

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5105

GoogleEPSS <= 49%CRITICAL2017-07-26

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

CVEs:CVE-2017-5105

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5106

GoogleEPSS <= 49%CRITICAL2017-07-26

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

CVEs:CVE-2017-5106

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5096

GoogleEPSS <= 49%CRITICAL2017-07-26

Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.

CVEs:CVE-2017-5096

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5100

GoogleEPSS <= 49%CRITICAL2017-07-26

A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-5100

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0673

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33974623.

CVEs:CVE-2017-0673

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0674

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231163.

CVEs:CVE-2017-0674

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0675

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.

CVEs:CVE-2017-0675

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0676

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34896431.

CVEs:CVE-2017-0676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0677

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36035074.

CVEs:CVE-2017-0677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0679

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36996978.

CVEs:CVE-2017-0679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0680

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37008096.

CVEs:CVE-2017-0680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0681

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37208566.

CVEs:CVE-2017-0681

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0682

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36588422.

CVEs:CVE-2017-0682

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0683

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36591008.

CVEs:CVE-2017-0683

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0701

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36385715.

CVEs:CVE-2017-0701

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0702

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36621442.

CVEs:CVE-2017-0702

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5109

GoogleEPSS <= 49%MEDIUM2017-07-26

Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.

CVEs:CVE-2017-5109

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-9245

GoogleEPSS <= 49%HIGH2017-07-19

The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL.

CVEs:CVE-2017-9245

Affected products

ProductStatusVendorPackageEcosystem
news_and_weather affected google
Upstream advisory

CVE-2017-0671

Open SourceEPSS <= 49%HIGH2017-07-06

A remote code execution vulnerability in the Android libraries. Product: Android. Versions: 4.4.4. Android ID: A-34514762.

CVEs:CVE-2017-0671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0691

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36724453.

CVEs:CVE-2017-0691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9062

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow vulnerability exists when loading an ELF file.

CVEs:CVE-2015-9062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9968

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the UIMDIAG interface.

CVEs:CVE-2014-9968

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9977

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in PlayReady DRM.

CVEs:CVE-2014-9977

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9978

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE service.

CVEs:CVE-2014-9978

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9041

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists when performing WCDMA radio tuning.

CVEs:CVE-2015-9041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9042

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists when processing a QMI message.

CVEs:CVE-2015-9042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9053

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the processing of certain responses from the USIM.

CVEs:CVE-2015-9053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10346

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in the hypervisor.

CVEs:CVE-2016-10346

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9038

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a NULL pointer may be dereferenced in the front end.

CVEs:CVE-2015-9038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9043

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a NULL pointer can be dereferenced upon the expiry of a timer.

CVEs:CVE-2015-9043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9054

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a NULL pointer can be dereferenced during GAL decoding.

CVEs:CVE-2015-9054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9411

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in rollback protection.

CVEs:CVE-2014-9411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9973

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missing in a PlayReady DRM routine.

CVEs:CVE-2014-9973

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9974

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing in Keymaster.

CVEs:CVE-2014-9974

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9979

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a variable is uninitialized in a TrustZone system call potentially leading to the compromise of secure memory.

CVEs:CVE-2014-9979

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9980

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a Sample App failed to check a length potentially leading to unauthorized access to secure memory.

CVEs:CVE-2014-9980

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8595

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in digital television/digital radio DRM.

CVEs:CVE-2015-8595

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8596

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths is missing in malware protection.

CVEs:CVE-2015-8596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9035

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a memory buffer fails to be freed after it is no longer needed potentially resulting in memory exhaustion.

CVEs:CVE-2015-9035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9036

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an incorrect length is used to clear a memory buffer resulting in adjacent memory getting corrupted.

CVEs:CVE-2015-9036

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9037

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read may occur in the processing of a downlink 3G NAS message.

CVEs:CVE-2015-9037

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9039

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an assertion can be reached by a sequence of downlink messages.

CVEs:CVE-2015-9039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9044

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.

CVEs:CVE-2015-9044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9045

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GERAN where a buffer can be overflown while taking power measurements.

CVEs:CVE-2015-9045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9046

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.

CVEs:CVE-2015-9046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9048

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of lost RTP packets.

CVEs:CVE-2015-9048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9049

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of certain responses from the USIM.

CVEs:CVE-2015-9049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9050

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists where an array out of bounds access can occur during a CA call.

CVEs:CVE-2015-9050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9051

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on a length in a System Information message.

CVEs:CVE-2015-9051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9052

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached while processing a downlink message.

CVEs:CVE-2015-9052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9055

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a memory management routine.

CVEs:CVE-2015-9055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9060

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not properly validated in a QTEE system call.

CVEs:CVE-2015-9060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9061

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length potentially leading to unauthorized access to secure memory.

CVEs:CVE-2015-9061

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9067

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a potential compiler optimization of memset() is addressed.

CVEs:CVE-2015-9067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9068

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a mink syscall is not properly validated.

CVEs:CVE-2015-9068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9069

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, the Secure File System can become corrupted.

CVEs:CVE-2015-9069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9070

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscall.

CVEs:CVE-2015-9070

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9071

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscall.

CVEs:CVE-2015-9071

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9072

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an untrusted pointer dereference can occur in a TrustZone syscall.

CVEs:CVE-2015-9072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9073

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an untrusted pointer dereference can occur in a TrustZone syscall.

CVEs:CVE-2015-9073

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10343

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, sSL handshake failure with ClientHello rejection results in memory leak.

CVEs:CVE-2016-10343

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10344

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in LTE.

CVEs:CVE-2016-10344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10347

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is not properly validated.

CVEs:CVE-2016-10347

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10388

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a configuration vulnerability exists when loading a 3rd-party QTEE application.

CVEs:CVE-2016-10388

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10391

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for validity.

CVEs:CVE-2016-10391

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5872

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are not properly validated.

CVEs:CVE-2016-5872

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9040

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.

CVEs:CVE-2015-9040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9047

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup.

CVEs:CVE-2015-9047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10382

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.

CVEs:CVE-2016-10382

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10383

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, there is a TOCTOU race condition in Secure UI.

CVEs:CVE-2016-10383

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5863

Open SourceEPSS <= 49%HIGH2017-07-06

In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.

CVEs:CVE-2016-5863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8260

Open SourceEPSS <= 49%CRITICAL2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and cause an out of bounds write later.

CVEs:CVE-2017-8260

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-0575

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuration.

CVEs:CVE-2015-0575

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8255

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in boot.

CVEs:CVE-2017-8255

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0664

Open SourceEPSS <= 49%HIGH2017-07-06

A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36491278.

CVEs:CVE-2017-0664

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0665

Open SourceEPSS <= 49%HIGH2017-07-06

A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36991414.

CVEs:CVE-2017-0665

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0667

Open SourceEPSS <= 49%HIGH2017-07-06

A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37478824.

CVEs:CVE-2017-0667

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0326

Open SourceEPSS <= 49%HIGH2017-07-06

An information disclosure vulnerability in the NVIDIA Video Driver due to an out-of-bounds read function in the Tegra Display Controller driver could result in possible information disclosure. This issue is rated as Moderate. Product: Android. Version:...

CVEs:CVE-2017-0326

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8243

Open SourceEPSS <= 49%HIGH2017-07-06

A buffer overflow can occur in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android when processing a firmware image file.

CVEs:CVE-2017-8243

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0666

Open SourceEPSS <= 49%HIGH2017-07-06

A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37285689.

CVEs:CVE-2017-0666

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10389

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.

CVEs:CVE-2016-10389

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8253

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel memory can potentially be overwritten if an invalid master is sent from userspace.

CVEs:CVE-2017-8253

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8259

Open SourceEPSS <= 49%CRITICAL2017-07-06

In the service locator in all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow can occur as the variable set for determining the size of the buffer is not used to indicate the size of the buffer.

CVEs:CVE-2017-8259

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8263

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a kernel fault can occur when doing certain operations on a read-only virtual address in userspace.

CVEs:CVE-2017-8263

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8268

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buffer processing with invalid values leading to the driver performing a heap buffer over-read.

CVEs:CVE-2017-8268

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0684

Open SourceEPSS <= 49%HIGH2017-07-06

A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.

CVEs:CVE-2017-0684

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0711

Open SourceEPSS <= 49%HIGH2017-07-06

A elevation of privilege vulnerability in the MediaTek networking driver. Product: Android. Versions: Android kernel. Android ID: A-36099953. References: M-ALPS03206781.

CVEs:CVE-2017-0711

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9975

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback vulnerability potentially exists in Full Disk Encryption.

CVEs:CVE-2014-9975

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0708

Open SourceEPSS <= 49%HIGH2017-07-06

A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.

CVEs:CVE-2017-0708

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0703

Open SourceEPSS <= 49%HIGH2017-07-06

A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33123882.

CVEs:CVE-2017-0703

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0669

Open SourceEPSS <= 49%HIGH2017-07-06

A information disclosure vulnerability in the Android framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34114752.

CVEs:CVE-2017-0669

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0668

Open SourceEPSS <= 49%HIGH2017-07-06

A information disclosure vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-22011579.

CVEs:CVE-2017-0668

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0698

Open SourceEPSS <= 49%HIGH2017-07-06

A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35467458.

CVEs:CVE-2017-0698

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0699

Open SourceEPSS <= 49%HIGH2017-07-06

A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36490809.

CVEs:CVE-2017-0699

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8273

Open SourceEPSS <= 49%CRITICAL2017-07-06

In all Qualcomm products with Android release from CAF using the Linux kernel, while processing fastboot boot command when verified boot feature is disabled, with length greater than boot image buffer, a buffer overflow can occur.

CVEs:CVE-2017-8273

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-7954

Open SourceEPSS <= 49%HIGH2017-07-07

Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target Android device to upload files outside of the sdcard...

CVEs:CVE-2014-7954

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0704

Open SourceEPSS <= 49%CRITICAL2017-07-06

A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-33059280.

CVEs:CVE-2017-0704

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0707

Open SourceEPSS <= 49%CRITICAL2017-07-06

A elevation of privilege vulnerability in the HTC led driver. Product: Android. Versions: Android kernel. Android ID: A-36088467.

CVEs:CVE-2017-0707

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0710

Open SourceEPSS <= 49%CRITICAL2017-07-06

A elevation of privilege vulnerability in the Upstream Linux tcb. Product: Android. Versions: Android kernel. Android ID: A-34951864.

CVEs:CVE-2017-0710

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0670

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36104177.

CVEs:CVE-2017-0670

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8254

Open SourceEPSS <= 49%MEDIUM2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an audio client pointer is dereferenced before being checked if it is valid.

CVEs:CVE-2017-8254

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8258

Open SourceEPSS <= 49%MEDIUM2017-07-06

An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver.

CVEs:CVE-2017-8258

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8267

Open SourceEPSS <= 49%CRITICAL2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in an IOCTL handler potentially leading to an integer overflow and then an out-of-bounds write.

CVEs:CVE-2017-8267

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8256

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, array out of bounds access can occur if userspace sends more than 16 multicast addresses.

CVEs:CVE-2017-8256

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8261

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in a camera driver ioctl, a kernel overwrite can potentially occur.

CVEs:CVE-2017-8261

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8271

Open SourceEPSS <= 49%HIGH2017-07-06

Out of bound memory write can happen in the MDSS Rotator driver in all Qualcomm products with Android releases from CAF using the Linux kernel by an unsanitized userspace-controlled parameter.

CVEs:CVE-2017-8271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8272

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in a driver function, a value from userspace is not properly validated potentially leading to an out of bounds heap write.

CVEs:CVE-2017-8272

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0685

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34203195.

CVEs:CVE-2017-0685

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0686

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231231.

CVEs:CVE-2017-0686

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0688

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35584425.

CVEs:CVE-2017-0688

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0689

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36215950.

CVEs:CVE-2017-0689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0692

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36725407.

CVEs:CVE-2017-0692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0693

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36993291.

CVEs:CVE-2017-0693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0694

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37093318.

CVEs:CVE-2017-0694

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0695

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37094889.

CVEs:CVE-2017-0695

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0696

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207120.

CVEs:CVE-2017-0696

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0697

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37239013.

CVEs:CVE-2017-0697

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-7953

Open SourceEPSS <= 49%HIGH2017-07-07

Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneousl...

CVEs:CVE-2014-7953

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0709

Open SourceEPSS <= 49%HIGH2017-07-06

A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.

CVEs:CVE-2017-0709

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8266

Open SourceEPSS <= 49%CRITICAL2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.

CVEs:CVE-2017-8266

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0690

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36592202.

CVEs:CVE-2017-0690

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0672

Open SourceEPSS <= 49%HIGH2017-07-06

A denial of service vulnerability in the Android libraries. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-34778578.

CVEs:CVE-2017-0672

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8270

Open SourceEPSS <= 49%CRITICAL2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a driver potentially leading to a use-after-free condition.

CVEs:CVE-2017-8270

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8257

Open SourceEPSS <= 49%HIGH2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while another process still has the debug...

CVEs:CVE-2017-8257

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8265

Open SourceEPSS <= 49%CRITICAL2017-07-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free.

CVEs:CVE-2017-8265

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10398

Open SourceEPSS <= 49%HIGH2017-07-14

Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay ...

CVEs:CVE-2016-10398

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0705

Open SourceEPSS <= 49%CRITICAL2017-07-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References: B-RB#119898.

CVEs:CVE-2017-0705

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0706

Open SourceEPSS <= 49%CRITICAL2017-07-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-35195787. References: B-RB#120532.

CVEs:CVE-2017-0706

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.