Google Security Advisories · September 2017 — Google Security Advisories
208 advisories 109 CVEs 3 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2017-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2017-8759

GoogleExploitedCISA KEV listedHIGH2017-09-13

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

CVEs:CVE-2017-8759

Affected products

ProductStatusVendorPackageEcosystem
.net_framework affected microsoft
Upstream advisory

CVE-2017-8759

Project ZeroExploitedCISA KEV listed2017-09-13

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

CVEs:CVE-2017-8759

Upstream advisory

CVE-2017-14496

Open SourceWeaponized exploitHIGH2017-09-18

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

CVEs:CVE-2017-14496

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
dnsmasq affected thekelleys
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
leap affected novell
ubuntu_linux affected canonical
Upstream advisory

CVE-2017-0781

Open SourceWeaponized exploitCRITICAL2017-09-14

A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

CVEs:CVE-2017-0781

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0785

Open SourceWeaponized exploitHIGH2017-09-14

A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.

CVEs:CVE-2017-0785

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2015-5237

Open SourcePoC exploitHIGH2017-09-25

DEBIAN-CVE-2015-5237

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Debian:11 protobuf
protobuf affected Debian:12 protobuf
protobuf affected Debian:13 protobuf
protobuf affected Debian:14 protobuf
Upstream advisory

PYSEC-2017-65

Open SourcePoC exploitHIGH2017-09-25

PYSEC-2017-65

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected PyPI protobuf
Upstream advisory

CVE-2015-5237

Open SourcePoC exploitHIGH2017-09-25

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

CVEs:CVE-2015-5237

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected google
Upstream advisory

CVE-2015-5237

Open SourcePoC exploitHIGH2017-09-25

protobuf susceptible to buffer overflow

CVEs:CVE-2015-5237

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-parent affected Maven com.google.protobuf:protobuf-parent
Google.Protobuf affected NuGet Google.Protobuf
protobuf affected PyPI protobuf
protobuf affected google google/protobuf
protocolbuffers/protobuf affected github.com github.com/protocolbuffers/protobuf
Upstream advisory

CVE-2015-5237

Open SourcePoC exploitHIGH2017-09-25

PYSEC-2017-65

CVEs:CVE-2015-5237

Affected products

ProductStatusVendorPackageEcosystem
com.google.protobuf:protobuf-parent affected Maven com.google.protobuf:protobuf-parent
Google.Protobuf affected NuGet Google.Protobuf
protobuf affected google google/protobuf
protobuf affected PyPI protobuf
protocolbuffers/protobuf affected github.com github.com/protocolbuffers/protobuf
Upstream advisory

CVE-2017-11041

Open SourcePoC exploitHIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thread and can be potentially freed in another.

CVEs:CVE-2017-11041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0783

Open SourcePoC exploitHIGH2017-09-14

A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.

CVEs:CVE-2017-0783

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-3985-1

Open SourceEPSS <= 49%2017-09-28

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

openSUSE-SU-2017:2482-1

Open SourceEPSS <= 49%CRITICAL2017-09-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2017:2491-1

Open SourceEPSS <= 49%CRITICAL2017-09-15

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

RHSA-2017:2676

Open SourceEPSS <= 49%HIGH2017-09-12

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

CVE-2017-5115

GoogleEPSS <= 49%HIGH2017-09-06

Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

CVEs:CVE-2017-5115

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-5116

GoogleEPSS <= 49%CRITICAL2017-09-06

Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2017-5116

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-1002003

Open SourceEPSS <= 49%CRITICAL2017-09-14

Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

CVEs:CVE-2017-1002003

Affected products

ProductStatusVendorPackageEcosystem
wp2android-turn-wp-site-into-android-app affected wp2android-turn-wp-site-into-android-app_project
Upstream advisory

RHSA-2017:2792

Open SourceEPSS <= 49%HIGH2017-09-25

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

openSUSE-SU-2017:2557-1

Open SourceEPSS <= 49%2017-09-23

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2017:2558-1

Open SourceEPSS <= 49%2017-09-23

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

CVE-2017-5121

GoogleEPSS <= 49%CRITICAL2017-09-22

Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.

CVEs:CVE-2017-5121

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5112

GoogleEPSS <= 49%CRITICAL2017-09-06

Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2017-5112

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2013-7429

GoogleEPSS <= 49%CRITICAL2017-09-14

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.

CVEs:CVE-2013-7429

Affected products

ProductStatusVendorPackageEcosystem
googlemaps affected mapsplugin
Upstream advisory

CVE-2017-0782

Open SourceEPSS <= 49%CRITICAL2017-09-14

A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146237.

CVEs:CVE-2017-0782

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2013-7428

GoogleEPSS <= 49%HIGH2017-09-07

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php.

CVEs:CVE-2013-7428

Affected products

ProductStatusVendorPackageEcosystem
googlemaps affected mapsplugin
Upstream advisory

CVE-2015-1537

Open SourceEPSS <= 49%HIGH2017-09-27

Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code via a crafted application.

CVEs:CVE-2015-1537

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5119

GoogleEPSS <= 49%HIGH2017-09-06

Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2017-5119

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-5117

GoogleEPSS <= 49%HIGH2017-09-06

Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2017-5117

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2017-14623

Open SourceEPSS <= 49%HIGH2017-09-20

DEBIAN-CVE-2017-14623

Affected products

ProductStatusVendorPackageEcosystem
golang-github-go-ldap-ldap affected Debian:11 golang-github-go-ldap-ldap
golang-github-go-ldap-ldap affected Debian:12 golang-github-go-ldap-ldap
golang-github-go-ldap-ldap affected Debian:13 golang-github-go-ldap-ldap
golang-github-go-ldap-ldap affected Debian:14 golang-github-go-ldap-ldap
Upstream advisory

RHBA-2017:2642

Open SourceEPSS <= 49%HIGH2017-09-08

Red Hat Bug Fix Advisory: OpenShift Container Platform 3.6.1 bug fix and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
atomic-openshift affected Red Hat:openshift:3.6::el7 atomic-openshift
atomic-openshift-clients affected Red Hat:openshift:3.6::el7 atomic-openshift-clients
atomic-openshift-clients-redistributable affected Red Hat:openshift:3.6::el7 atomic-openshift-clients-redistributable
atomic-openshift-cluster-capacity affected Red Hat:openshift:3.6::el7 atomic-openshift-cluster-capacity
atomic-openshift-docker-excluder affected Red Hat:openshift:3.6::el7 atomic-openshift-docker-excluder
atomic-openshift-dockerregistry affected Red Hat:openshift:3.6::el7 atomic-openshift-dockerregistry
atomic-openshift-excluder affected Red Hat:openshift:3.6::el7 atomic-openshift-excluder
atomic-openshift-federation-services affected Red Hat:openshift:3.6::el7 atomic-openshift-federation-services
atomic-openshift-master affected Red Hat:openshift:3.6::el7 atomic-openshift-master
atomic-openshift-node affected Red Hat:openshift:3.6::el7 atomic-openshift-node
atomic-openshift-pod affected Red Hat:openshift:3.6::el7 atomic-openshift-pod
atomic-openshift-sdn-ovs affected Red Hat:openshift:3.6::el7 atomic-openshift-sdn-ovs
atomic-openshift-service-catalog affected Red Hat:openshift:3.6::el7 atomic-openshift-service-catalog
atomic-openshift-tests affected Red Hat:openshift:3.6::el7 atomic-openshift-tests
fluentd affected Red Hat:openshift:3.6::el7 fluentd
fluentd-doc affected Red Hat:openshift:3.6::el7 fluentd-doc
jenkins-2-plugins affected Red Hat:openshift:3.6::el7 jenkins-2-plugins
kibana affected Red Hat:openshift:3.6::el7 kibana
kibana-debuginfo affected Red Hat:openshift:3.6::el7 kibana-debuginfo
rubygem-cool.io affected Red Hat:openshift:3.6::el7 rubygem-cool.io
rubygem-cool.io-debuginfo affected Red Hat:openshift:3.6::el7 rubygem-cool.io-debuginfo
rubygem-cool.io-doc affected Red Hat:openshift:3.6::el7 rubygem-cool.io-doc
rubygem-excon affected Red Hat:openshift:3.6::el7 rubygem-excon
rubygem-excon-doc affected Red Hat:openshift:3.6::el7 rubygem-excon-doc
rubygem-faraday affected Red Hat:openshift:3.6::el7 rubygem-faraday
rubygem-faraday-doc affected Red Hat:openshift:3.6::el7 rubygem-faraday-doc
rubygem-fluent-plugin-kubernetes_metadata_filter affected Red Hat:openshift:3.6::el7 rubygem-fluent-plugin-kubernetes_metadata_filter
rubygem-fluent-plugin-kubernetes_metadata_filter-doc affected Red Hat:openshift:3.6::el7 rubygem-fluent-plugin-kubernetes_metadata_filter-doc
rubygem-fluent-plugin-viaq_data_model affected Red Hat:openshift:3.6::el7 rubygem-fluent-plugin-viaq_data_model
rubygem-fluent-plugin-viaq_data_model-doc affected Red Hat:openshift:3.6::el7 rubygem-fluent-plugin-viaq_data_model-doc
rubygem-i18n affected Red Hat:openshift:3.6::el7 rubygem-i18n
rubygem-i18n-doc affected Red Hat:openshift:3.6::el7 rubygem-i18n-doc
rubygem-systemd-journal affected Red Hat:openshift:3.6::el7 rubygem-systemd-journal
rubygem-systemd-journal-doc affected Red Hat:openshift:3.6::el7 rubygem-systemd-journal-doc
tuned-profiles-atomic-openshift-node affected Red Hat:openshift:3.6::el7 tuned-profiles-atomic-openshift-node
Upstream advisory

CVE-2014-9686

GoogleEPSS <= 49%MEDIUM2017-09-27

The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists ...

CVEs:CVE-2014-9686

Affected products

ProductStatusVendorPackageEcosystem
googlemaps affected mapsplugin
Upstream advisory

CVE-2017-0758

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492741.

CVEs:CVE-2017-0758

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0760

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237396.

CVEs:CVE-2017-0760

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0761

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38448381.

CVEs:CVE-2017-0761

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0764

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872015.

CVEs:CVE-2017-0764

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5122

GoogleEPSS <= 49%HIGH2017-09-22

Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.

CVEs:CVE-2017-5122

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2017-1002100

Open SourceEPSS <= 49%MEDIUM2017-09-14

Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to t...

CVEs:CVE-2017-1002100

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2017-5114

GoogleEPSS <= 49%CRITICAL2017-09-06

Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.

CVEs:CVE-2017-5114

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5113

GoogleEPSS <= 49%HIGH2017-09-06

Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2017-5113

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5111

GoogleEPSS <= 49%CRITICAL2017-09-06

A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.

CVEs:CVE-2017-5111

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2015-4697

GoogleEPSS <= 49%HIGH2017-09-07

Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.

CVEs:CVE-2015-4697

Affected products

ProductStatusVendorPackageEcosystem
google_analyticator affected sumo
Upstream advisory

CVE-2017-9725

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.

CVEs:CVE-2017-9725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-5118

GoogleEPSS <= 49%MEDIUM2017-09-06

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a c...

CVEs:CVE-2017-5118

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-5120

GoogleEPSS <= 49%MEDIUM2017-09-06

Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted ...

CVEs:CVE-2017-5120

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-0753

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android libraries (libgdx). Product: Android. Versions: 7.1.1, 7.1.2, 8.0. Android ID: A-62218744.

CVEs:CVE-2017-0753

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0757

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36006815.

CVEs:CVE-2017-0757

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0759

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36715268.

CVEs:CVE-2017-0759

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0762

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62214264.

CVEs:CVE-2017-0762

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0763

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62534693.

CVEs:CVE-2017-0763

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0765

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872863.

CVEs:CVE-2017-0765

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0766

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libjhead). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37776688.

CVEs:CVE-2017-0766

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0756

Open SourceEPSS <= 49%HIGH2017-09-06

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34621073.

CVEs:CVE-2017-0756

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-1526

Open SourceEPSS <= 49%HIGH2017-09-27

The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.

CVEs:CVE-2015-1526

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8278

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, while reading audio data from an unspecified driver, a buffer overflow or integer overflow could occur.

CVEs:CVE-2017-8278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0778

Open SourceEPSS <= 49%HIGH2017-09-06

A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.

CVEs:CVE-2017-0778

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0786

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37351060. References: B-V2017060101.

CVEs:CVE-2017-0786

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-10998

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is fully within the valid region. If the buffer length i...

CVEs:CVE-2017-10998

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2017-0752

Open SourceEPSS <= 49%CRITICAL2017-09-08

DEBIAN-CVE-2017-0752

Affected products

ProductStatusVendorPackageEcosystem
android-framework-23 affected Debian:11 android-framework-23
Upstream advisory

CVE-2017-0752

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.

CVEs:CVE-2017-0752

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-10996

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memor...

CVEs:CVE-2017-10996

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0794

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Versions: Android kernel. Android ID: A-35644812.

CVEs:CVE-2017-0794

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0798

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36100671. References: M-ALPS03365532.

CVEs:CVE-2017-0798

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0799

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.

CVEs:CVE-2017-0799

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0800

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-37683975. References: M-ALPS03302988.

CVEs:CVE-2017-0800

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0801

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.

CVEs:CVE-2017-0801

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0755

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the Android libraries (libminikin). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-32178311.

CVEs:CVE-2017-0755

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0767

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37536407.

CVEs:CVE-2017-0767

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0768

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62019992.

CVEs:CVE-2017-0768

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0769

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37662122.

CVEs:CVE-2017-0769

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0770

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38234812.

CVEs:CVE-2017-0770

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0795

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36198473. References: M-ALPS03361480.

CVEs:CVE-2017-0795

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0796

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Android ID: A-62458865. References: M-ALPS03353884, M-ALPS03353886, M-ALPS03353887.

CVEs:CVE-2017-0796

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0797

Open SourceEPSS <= 49%HIGH2017-09-06

A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.

CVEs:CVE-2017-0797

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8247

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once. This would lead to get_pid being called more than once, however p...

CVEs:CVE-2017-8247

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8250

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overflow to buffer overflow (with a smaller buffer allocat...

CVEs:CVE-2017-8250

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0793

Open SourceEPSS <= 49%HIGH2017-09-06

A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.

CVEs:CVE-2017-0793

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9724

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, specifically the ION cache maintenance code is writing to a user supplied address.

CVEs:CVE-2017-9724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0776

Open SourceEPSS <= 49%HIGH2017-09-06

A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.

CVEs:CVE-2017-0776

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0777

Open SourceEPSS <= 49%HIGH2017-09-06

A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.

CVEs:CVE-2017-0777

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8251

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cmd & msm_isp_stats_update_cgc_override, 'stream_cfg_cmd->num_streams' is not checked, and could overflow the array stream_cfg_cmd->st...

CVEs:CVE-2017-8251

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0802

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36232120. References: M-ALPS03384818.

CVEs:CVE-2017-0802

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0803

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36136137. References: M-ALPS03361477.

CVEs:CVE-2017-0803

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0804

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the MediaTek mmc driver. Product: Android. Versions: Android kernel. Android ID: A-36274676. References: M-ALPS03361487.

CVEs:CVE-2017-0804

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-10997

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.

CVEs:CVE-2017-10997

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-10999

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.

CVEs:CVE-2017-10999

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11000

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.

CVEs:CVE-2017-11000

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11001

Open SourceEPSS <= 49%MEDIUM2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.

CVEs:CVE-2017-11001

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11002

Open SourceEPSS <= 49%MEDIUM2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.

CVEs:CVE-2017-11002

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11040

Open SourceEPSS <= 49%MEDIUM2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.

CVEs:CVE-2017-11040

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0779

Open SourceEPSS <= 49%HIGH2017-09-06

A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38340117.

CVEs:CVE-2017-0779

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8281

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.

CVEs:CVE-2017-8281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8277

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_dba_register_client, if the client registers failed, it would be freed. However the client was not removed from list. Use-after-free would occur when tr...

CVEs:CVE-2017-8277

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9720

Open SourceEPSS <= 49%HIGH2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one error in a camera driver, an out-of-bounds read/write can occur.

CVEs:CVE-2017-9720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0771

Open SourceEPSS <= 49%HIGH2017-09-06

A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37624243.

CVEs:CVE-2017-0771

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0772

Open SourceEPSS <= 49%HIGH2017-09-06

A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38115076.

CVEs:CVE-2017-0772

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0773

Open SourceEPSS <= 49%HIGH2017-09-06

A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37615911.

CVEs:CVE-2017-0773

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0774

Open SourceEPSS <= 49%HIGH2017-09-06

A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62673844.

CVEs:CVE-2017-0774

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0775

Open SourceEPSS <= 49%HIGH2017-09-06

A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673179.

CVEs:CVE-2017-0775

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0780

Open SourceEPSS <= 49%HIGH2017-09-06

A denial of service vulnerability in the Android runtime (android messenger). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37742976.

CVEs:CVE-2017-0780

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9677

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks. If one thread is...

CVEs:CVE-2017-9677

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-8280

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow during the context...

CVEs:CVE-2017-8280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0787

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722970. References: B-V2017053104.

CVEs:CVE-2017-0787

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0788

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722328. References: B-V2017053103.

CVEs:CVE-2017-0788

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0789

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37685267. References: B-V2017053102.

CVEs:CVE-2017-0789

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0790

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37357704. References: B-V2017053101.

CVEs:CVE-2017-0790

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0791

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37306719. References: B-V2017052302.

CVEs:CVE-2017-0791

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9676

Open SourceEPSS <= 49%CRITICAL2017-09-06

In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock.

CVEs:CVE-2017-9676

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0784

Open SourceEPSS <= 49%CRITICAL2017-09-06

A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.

CVEs:CVE-2017-0784

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-1527

Open SourceEPSS <= 49%HIGH2017-09-15

Integer overflow in IAudioPolicyService.cpp in Android allows local users to gain privileges via a crafted application, aka Android Bug ID 19261727.

CVEs:CVE-2015-1527

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0792

Open SourceEPSS <= 49%HIGH2017-09-06

A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.

CVEs:CVE-2017-0792

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.