Advisories
Open SourceExploitedCISA KEV listedCRITICAL2017-08-28
Chromium-browser 60.0.3112.101 fixes security issues
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:5 |
chromium-browser-stable |
— |
| chromium-browser-stable |
affected |
Mageia:6 |
chromium-browser-stable |
— |
| libwebp |
affected |
Mageia:5 |
libwebp |
— |
GooglePoC exploitHIGH2017-08-08
CVEs:CVE-2017-0719
Open SourcePoC exploitHIGH2017-08-08
A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.
CVEs:CVE-2017-0719
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-08-08
A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37712181.
CVEs:CVE-2017-0739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-08-08
CVEs:CVE-2017-0739
GooglePoC exploitMEDIUM2017-08-07
CVEs:CVE-2015-3839
Open SourcePoC exploitMEDIUM2017-08-07
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
CVEs:CVE-2015-3839
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-08-08
The length of attribute value for STA_EXT_CAPABILITY in __wlan_hdd_change_station in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-06 being less than the actual lenth of StaParams.extn_capability results in a read for extra bytes ...
CVEs:CVE-2017-9693
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2017-08-08
CVEs:CVE-2017-9693
Open SourceEPSS <= 49%2017-08-04
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:9 |
chromium-browser |
— |
Open SourceEPSS <= 49%MEDIUM2017-08-01
Red Hat Security Advisory: golang security, bug fix, and enhancement update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang |
affected |
Red Hat:enterprise_linux:7::server |
golang |
— |
| golang-bin |
affected |
Red Hat:enterprise_linux:7::server |
golang-bin |
— |
| golang-docs |
affected |
Red Hat:enterprise_linux:7::server |
golang-docs |
— |
| golang-misc |
affected |
Red Hat:enterprise_linux:7::server |
golang-misc |
— |
| golang-src |
affected |
Red Hat:enterprise_linux:7::server |
golang-src |
— |
| golang-tests |
affected |
Red Hat:enterprise_linux:7::server |
golang-tests |
— |
GoogleEPSS <= 49%HIGH2017-08-29
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.
CVEs:CVE-2013-7432
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlemaps |
affected |
mapsplugin |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-29
CVEs:CVE-2013-7432
Open SourceEPSS <= 49%LOW2017-08-07
Kubernetes in OpenShift3 Access Control Misconfiguration
CVEs:CVE-2015-7561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourceEPSS <= 49%LOW2017-08-07
Kubernetes in OpenShift3 Access Control Misconfiguration
CVEs:CVE-2015-7561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourceEPSS <= 49%LOW2017-08-07
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.
CVEs:CVE-2015-7561
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
| openshift |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0714
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492637.
CVEs:CVE-2017-0714
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.
CVEs:CVE-2017-0718
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0718
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.
CVEs:CVE-2017-0720
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0720
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0722
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37660827.
CVEs:CVE-2017-0722
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37079296.
CVEs:CVE-2017-0745
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0745
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.
CVEs:CVE-2015-8593
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-8593
GoogleEPSS <= 49%MEDIUM2017-08-29
CVEs:CVE-2013-7431
GoogleEPSS <= 49%MEDIUM2017-08-29
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
CVEs:CVE-2013-7431
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlemaps |
affected |
mapsplugin |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36998372.
CVEs:CVE-2017-0715
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0715
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37203196.
CVEs:CVE-2017-0716
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0716
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0721
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37561455.
CVEs:CVE-2017-0721
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0723
Open SourceEPSS <= 49%HIGH2017-08-08
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37968755.
CVEs:CVE-2017-0723
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-8594
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in RFA-1x.
CVEs:CVE-2015-8594
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.
CVEs:CVE-2014-9976
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2014-9976
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a procedure involving a remote UIM client.
CVEs:CVE-2015-9063
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-9063
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an Inter-RAT procedure.
CVEs:CVE-2015-9066
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-9066
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-0574
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.
CVEs:CVE-2015-0574
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-9065
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access Stratum security is established.
CVEs:CVE-2015-9065
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10380
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.
CVEs:CVE-2016-10380
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10381
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.
CVEs:CVE-2016-10381
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2014-9971
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.
CVEs:CVE-2014-9971
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2014-9972
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.
CVEs:CVE-2014-9972
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient during boot.
CVEs:CVE-2014-9981
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2014-9981
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10384
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a WLAN driver ioctl.
CVEs:CVE-2016-10384
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10386
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.
CVEs:CVE-2016-10386
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10387
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.
CVEs:CVE-2016-10387
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive amount of memory may be consumed.
CVEs:CVE-2016-10390
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10390
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10392
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.
CVEs:CVE-2016-10392
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013.
CVEs:CVE-2017-0750
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0750
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow vulnerability exists when loading an image file.
CVEs:CVE-2016-5871
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-5871
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-9064
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request before NAS security has been activated.
CVEs:CVE-2015-9064
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2016-10385
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a use-after-free vulnerability exists in IMS RCS.
CVEs:CVE-2016-10385
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a string can fail to be null-terminated in SIP leading to a buffer overflow.
CVEs:CVE-2015-9034
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-9034
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735.
CVEs:CVE-2017-0749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0749
GoogleEPSS <= 49%MEDIUM2017-08-29
CVEs:CVE-2013-7433
GoogleEPSS <= 49%CRITICAL2017-08-29
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.
CVEs:CVE-2013-7433
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlemaps |
affected |
mapsplugin |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2015-8592
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not validated prior to being dereferenced potentially resulting in Guest-OS memory corruption.
CVEs:CVE-2015-8592
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-28
CVEs:CVE-2013-7430
GoogleEPSS <= 49%CRITICAL2017-08-28
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.
CVEs:CVE-2013-7430
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlemaps |
affected |
mapsplugin |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0713
Open SourceEPSS <= 49%CRITICAL2017-08-08
A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-32096780.
CVEs:CVE-2017-0713
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-08-08
A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488. References: B-RB#116402.
CVEs:CVE-2017-0740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0740
Open SourceEPSS <= 49%CRITICAL2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in HSDPA.
CVEs:CVE-2015-0576
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-18
CVEs:CVE-2015-0576
Open SourceEPSS <= 49%HIGH2017-08-08
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory contents can leak to system logs.
CVEs:CVE-2017-9679
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-9679
Open SourceEPSS <= 49%HIGH2017-08-08
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a driver may use an uninitialized structure to log an error message.
CVEs:CVE-2017-9680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-9680
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a WLAN driver can lead to a Use After Free condition.
CVEs:CVE-2017-9685
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-18
CVEs:CVE-2017-9685
Open SourceEPSS <= 49%HIGH2017-08-08
A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.
CVEs:CVE-2017-0738
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0738
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-9678
Open SourceEPSS <= 49%HIGH2017-08-08
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a video driver, memory corruption can potentially occur due to lack of bounds checking in a memcpy().
CVEs:CVE-2017-9678
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-11
CVEs:CVE-2017-8269
Open SourceEPSS <= 49%MEDIUM2017-08-11
Userspace-controlled non null terminated parameter for IPA WAN ioctl in all Qualcomm products with Android releases from CAF using the Linux kernel can lead to exposure of kernel memory.
CVEs:CVE-2017-8269
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563942.
CVEs:CVE-2017-0737
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0737
Open SourceEPSS <= 49%HIGH2017-08-24
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.
CVEs:CVE-2017-0805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-24
CVEs:CVE-2017-0805
Open SourceEPSS <= 49%HIGH2017-08-08
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris_vidioc_s_ext_ctrls ioctl, it will print kernel addre...
CVEs:CVE-2017-9681
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-9681
Open SourceEPSS <= 49%HIGH2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure cryptographic algorithm.
CVEs:CVE-2014-9969
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-08-18
CVEs:CVE-2014-9969
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0748
Open SourceEPSS <= 49%HIGH2017-08-08
An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.
CVEs:CVE-2017-0748
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.
CVEs:CVE-2017-0725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0725
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207928.
CVEs:CVE-2017-0712
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0712
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Android media framework (mediadrmserver). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37710346.
CVEs:CVE-2017-0729
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0729
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36075363.
CVEs:CVE-2017-0731
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0731
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37504237.
CVEs:CVE-2017-0732
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0732
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the MediaTek gpu driver. Product: Android. Versions: Android kernel. Android ID: A-32458601. References: M-ALPS03007523.
CVEs:CVE-2017-0741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0741
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: Android kernel. Android ID: A-36074857. References: M-ALPS03275524.
CVEs:CVE-2017-0742
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0742
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0746
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392.
CVEs:CVE-2017-0746
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0747
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel. Android ID: A-32524214. References: QC-CR#2044821.
CVEs:CVE-2017-0747
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-11
CVEs:CVE-2017-8264
Open SourceEPSS <= 49%HIGH2017-08-11
A userspace process can cause a Denial of Service in the camera driver in all Qualcomm products with Android releases from CAF using the Linux kernel.
CVEs:CVE-2017-8264
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-08-08
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a USB driver can lead to a Use After Free condition.
CVEs:CVE-2017-9684
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-9684
Open SourceEPSS <= 49%CRITICAL2017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, in some memory allocation and free functions, a race condition can potentially occur leading to a Use After Free condition.
CVEs:CVE-2017-8262
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-18
CVEs:CVE-2017-8262
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0728
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37469795.
CVEs:CVE-2017-0728
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38487564.
CVEs:CVE-2017-0736
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0736
Open SourceEPSS <= 49%HIGH2017-08-18
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35583675.
CVEs:CVE-2017-0687
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-18
CVEs:CVE-2017-0687
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0724
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36819262.
CVEs:CVE-2017-0724
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36389123.
CVEs:CVE-2017-0726
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0726
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0730
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (h264 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36279112.
CVEs:CVE-2017-0730
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38391487.
CVEs:CVE-2017-0733
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0733
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38014992.
CVEs:CVE-2017-0734
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0734
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0735
Open SourceEPSS <= 49%HIGH2017-08-08
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38239864.
CVEs:CVE-2017-0735
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-0727
Open SourceEPSS <= 49%CRITICAL2017-08-08
A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.
CVEs:CVE-2017-0727
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-08-08
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.
CVEs:CVE-2017-9682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-9682
Open SourceEPSS <= 49%HIGH2017-08-08
When an atomic commit is issued on a writeback panel with a NULL output_layer parameter in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-03, a NULL pointer dereference may potentially occur.
CVEs:CVE-2017-9692
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-08-08
CVEs:CVE-2017-9692
Open SourceEPSS <= 49%CRITICAL2017-08-08
An elevation of privilege vulnerability in the NVIDIA firmware processing code. Product: Android. Versions: Android kernel. Android ID: A-34112726. References: N-CVE-2017-0744.
CVEs:CVE-2017-0744
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0744
Open SourceEPSS <= 49%CRITICAL2017-08-08
An elevation of privilege vulnerability in the Qualcomm QCE driver. Product: Android. Versions: Android kernel. Android ID: A-36591162. References: QC-CR#2045061.
CVEs:CVE-2017-0751
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-0751
GoogleEPSS <= 49%MEDIUM2017-08-08
CVEs:CVE-2017-9691
Open SourceEPSS <= 49%MEDIUM2017-08-08
There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicore driver.
CVEs:CVE-2017-9691
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |