Google Security Advisories · August 2017 — Google Security Advisories
170 advisories 86 CVEs 1 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2017-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

MGASA-2017-0317

Open SourceExploitedCISA KEV listedCRITICAL2017-08-28

Chromium-browser 60.0.3112.101 fixes security issues

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
chromium-browser-stable affected Mageia:6 chromium-browser-stable
libwebp affected Mageia:5 libwebp
Upstream advisory

CVE-2017-0719

Open SourcePoC exploitHIGH2017-08-08

A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.

CVEs:CVE-2017-0719

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0739

Open SourcePoC exploitHIGH2017-08-08

A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37712181.

CVEs:CVE-2017-0739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3839

Open SourcePoC exploitMEDIUM2017-08-07

The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).

CVEs:CVE-2015-3839

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9693

Open SourcePoC exploitHIGH2017-08-08

The length of attribute value for STA_EXT_CAPABILITY in __wlan_hdd_change_station in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-06 being less than the actual lenth of StaParams.extn_capability results in a read for extra bytes ...

CVEs:CVE-2017-9693

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-3926-1

Open SourceEPSS <= 49%2017-08-04

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

RHSA-2017:1859

Open SourceEPSS <= 49%MEDIUM2017-08-01

Red Hat Security Advisory: golang security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:7::server golang
golang-bin affected Red Hat:enterprise_linux:7::server golang-bin
golang-docs affected Red Hat:enterprise_linux:7::server golang-docs
golang-misc affected Red Hat:enterprise_linux:7::server golang-misc
golang-src affected Red Hat:enterprise_linux:7::server golang-src
golang-tests affected Red Hat:enterprise_linux:7::server golang-tests
Upstream advisory

CVE-2013-7432

GoogleEPSS <= 49%HIGH2017-08-29

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.

CVEs:CVE-2013-7432

Affected products

ProductStatusVendorPackageEcosystem
googlemaps affected mapsplugin
Upstream advisory

CVE-2015-7561

Open SourceEPSS <= 49%LOW2017-08-07

Kubernetes in OpenShift3 Access Control Misconfiguration

CVEs:CVE-2015-7561

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2015-7561

Open SourceEPSS <= 49%LOW2017-08-07

Kubernetes in OpenShift3 Access Control Misconfiguration

CVEs:CVE-2015-7561

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2015-7561

Open SourceEPSS <= 49%LOW2017-08-07

Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.

CVEs:CVE-2015-7561

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift affected redhat
Upstream advisory

CVE-2017-0714

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492637.

CVEs:CVE-2017-0714

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0718

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.

CVEs:CVE-2017-0718

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0720

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.

CVEs:CVE-2017-0720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0722

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37660827.

CVEs:CVE-2017-0722

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0745

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37079296.

CVEs:CVE-2017-0745

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8593

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.

CVEs:CVE-2015-8593

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2013-7431

GoogleEPSS <= 49%MEDIUM2017-08-29

Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.

CVEs:CVE-2013-7431

Affected products

ProductStatusVendorPackageEcosystem
googlemaps affected mapsplugin
Upstream advisory

CVE-2017-0715

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36998372.

CVEs:CVE-2017-0715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0716

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37203196.

CVEs:CVE-2017-0716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0721

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37561455.

CVEs:CVE-2017-0721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0723

Open SourceEPSS <= 49%HIGH2017-08-08

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37968755.

CVEs:CVE-2017-0723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8594

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in RFA-1x.

CVEs:CVE-2015-8594

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9976

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.

CVEs:CVE-2014-9976

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9063

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a procedure involving a remote UIM client.

CVEs:CVE-2015-9063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9066

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an Inter-RAT procedure.

CVEs:CVE-2015-9066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-0574

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.

CVEs:CVE-2015-0574

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9065

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access Stratum security is established.

CVEs:CVE-2015-9065

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10380

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.

CVEs:CVE-2016-10380

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10381

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.

CVEs:CVE-2016-10381

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9971

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.

CVEs:CVE-2014-9971

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9972

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.

CVEs:CVE-2014-9972

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9981

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, an overflow check in the USB interface was insufficient during boot.

CVEs:CVE-2014-9981

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10384

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a WLAN driver ioctl.

CVEs:CVE-2016-10384

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10386

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.

CVEs:CVE-2016-10386

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10387

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.

CVEs:CVE-2016-10387

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10390

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive amount of memory may be consumed.

CVEs:CVE-2016-10390

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10392

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.

CVEs:CVE-2016-10392

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0750

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013.

CVEs:CVE-2017-0750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5871

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow vulnerability exists when loading an image file.

CVEs:CVE-2016-5871

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9064

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request before NAS security has been activated.

CVEs:CVE-2015-9064

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-10385

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a use-after-free vulnerability exists in IMS RCS.

CVEs:CVE-2016-10385

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-9034

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a string can fail to be null-terminated in SIP leading to a buffer overflow.

CVEs:CVE-2015-9034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0749

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735.

CVEs:CVE-2017-0749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2013-7433

GoogleEPSS <= 49%CRITICAL2017-08-29

Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.

CVEs:CVE-2013-7433

Affected products

ProductStatusVendorPackageEcosystem
googlemaps affected mapsplugin
Upstream advisory

CVE-2015-8592

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not validated prior to being dereferenced potentially resulting in Guest-OS memory corruption.

CVEs:CVE-2015-8592

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2013-7430

GoogleEPSS <= 49%CRITICAL2017-08-28

Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.

CVEs:CVE-2013-7430

Affected products

ProductStatusVendorPackageEcosystem
googlemaps affected mapsplugin
Upstream advisory

CVE-2017-0713

Open SourceEPSS <= 49%CRITICAL2017-08-08

A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-32096780.

CVEs:CVE-2017-0713

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0740

Open SourceEPSS <= 49%CRITICAL2017-08-08

A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488. References: B-RB#116402.

CVEs:CVE-2017-0740

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-0576

Open SourceEPSS <= 49%CRITICAL2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in HSDPA.

CVEs:CVE-2015-0576

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9679

Open SourceEPSS <= 49%HIGH2017-08-08

In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory contents can leak to system logs.

CVEs:CVE-2017-9679

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9680

Open SourceEPSS <= 49%HIGH2017-08-08

In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a driver may use an uninitialized structure to log an error message.

CVEs:CVE-2017-9680

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9685

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a WLAN driver can lead to a Use After Free condition.

CVEs:CVE-2017-9685

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0738

Open SourceEPSS <= 49%HIGH2017-08-08

A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.

CVEs:CVE-2017-0738

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9678

Open SourceEPSS <= 49%HIGH2017-08-08

In all Qualcomm products with Android releases from CAF using the Linux kernel, in a video driver, memory corruption can potentially occur due to lack of bounds checking in a memcpy().

CVEs:CVE-2017-9678

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8269

Open SourceEPSS <= 49%MEDIUM2017-08-11

Userspace-controlled non null terminated parameter for IPA WAN ioctl in all Qualcomm products with Android releases from CAF using the Linux kernel can lead to exposure of kernel memory.

CVEs:CVE-2017-8269

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0737

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563942.

CVEs:CVE-2017-0737

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0805

Open SourceEPSS <= 49%HIGH2017-08-24

A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.

CVEs:CVE-2017-0805

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9681

Open SourceEPSS <= 49%HIGH2017-08-08

In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris_vidioc_s_ext_ctrls ioctl, it will print kernel addre...

CVEs:CVE-2017-9681

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9969

Open SourceEPSS <= 49%HIGH2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure cryptographic algorithm.

CVEs:CVE-2014-9969

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0748

Open SourceEPSS <= 49%HIGH2017-08-08

An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.

CVEs:CVE-2017-0748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0725

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.

CVEs:CVE-2017-0725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0712

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207928.

CVEs:CVE-2017-0712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0729

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Android media framework (mediadrmserver). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37710346.

CVEs:CVE-2017-0729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0731

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36075363.

CVEs:CVE-2017-0731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0732

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37504237.

CVEs:CVE-2017-0732

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0741

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the MediaTek gpu driver. Product: Android. Versions: Android kernel. Android ID: A-32458601. References: M-ALPS03007523.

CVEs:CVE-2017-0741

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0742

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: Android kernel. Android ID: A-36074857. References: M-ALPS03275524.

CVEs:CVE-2017-0742

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0746

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392.

CVEs:CVE-2017-0746

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0747

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel. Android ID: A-32524214. References: QC-CR#2044821.

CVEs:CVE-2017-0747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8264

Open SourceEPSS <= 49%HIGH2017-08-11

A userspace process can cause a Denial of Service in the camera driver in all Qualcomm products with Android releases from CAF using the Linux kernel.

CVEs:CVE-2017-8264

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9684

Open SourceEPSS <= 49%CRITICAL2017-08-08

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a USB driver can lead to a Use After Free condition.

CVEs:CVE-2017-9684

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8262

Open SourceEPSS <= 49%CRITICAL2017-08-18

In all Qualcomm products with Android releases from CAF using the Linux kernel, in some memory allocation and free functions, a race condition can potentially occur leading to a Use After Free condition.

CVEs:CVE-2017-8262

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0728

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37469795.

CVEs:CVE-2017-0728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0736

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38487564.

CVEs:CVE-2017-0736

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0687

Open SourceEPSS <= 49%HIGH2017-08-18

A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35583675.

CVEs:CVE-2017-0687

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0724

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36819262.

CVEs:CVE-2017-0724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0726

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36389123.

CVEs:CVE-2017-0726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0730

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (h264 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36279112.

CVEs:CVE-2017-0730

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0733

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38391487.

CVEs:CVE-2017-0733

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0734

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38014992.

CVEs:CVE-2017-0734

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0735

Open SourceEPSS <= 49%HIGH2017-08-08

A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38239864.

CVEs:CVE-2017-0735

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0727

Open SourceEPSS <= 49%CRITICAL2017-08-08

A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.

CVEs:CVE-2017-0727

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9682

Open SourceEPSS <= 49%CRITICAL2017-08-08

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.

CVEs:CVE-2017-9682

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9692

Open SourceEPSS <= 49%HIGH2017-08-08

When an atomic commit is issued on a writeback panel with a NULL output_layer parameter in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-03, a NULL pointer dereference may potentially occur.

CVEs:CVE-2017-9692

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0744

Open SourceEPSS <= 49%CRITICAL2017-08-08

An elevation of privilege vulnerability in the NVIDIA firmware processing code. Product: Android. Versions: Android kernel. Android ID: A-34112726. References: N-CVE-2017-0744.

CVEs:CVE-2017-0744

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0751

Open SourceEPSS <= 49%CRITICAL2017-08-08

An elevation of privilege vulnerability in the Qualcomm QCE driver. Product: Android. Versions: Android kernel. Android ID: A-36591162. References: QC-CR#2045061.

CVEs:CVE-2017-0751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9691

Open SourceEPSS <= 49%MEDIUM2017-08-08

There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicore driver.

CVEs:CVE-2017-9691

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.