Advisories
GoogleExploitedCISA KEV listedHIGH2017-09-13
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
CVEs:CVE-2017-8759
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| .net_framework |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2017-09-13
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
CVEs:CVE-2017-8759
GoogleExploitedCISA KEV listedHIGH2017-09-13
CVEs:CVE-2017-8759
GoogleWeaponized exploitHIGH2017-10-02
CVEs:CVE-2017-14496
Open SourceWeaponized exploitHIGH2017-09-18
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
CVEs:CVE-2017-14496
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| dnsmasq |
affected |
thekelleys |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| leap |
affected |
novell |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
Open SourceWeaponized exploitCRITICAL2017-09-14
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.
CVEs:CVE-2017-0781
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleWeaponized exploitHIGH2017-09-14
CVEs:CVE-2017-0781
GoogleWeaponized exploitMEDIUM2017-09-14
CVEs:CVE-2017-0785
Open SourceWeaponized exploitHIGH2017-09-14
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
CVEs:CVE-2017-0785
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-09-25
DEBIAN-CVE-2015-5237
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
Debian:11 |
protobuf |
— |
| protobuf |
affected |
Debian:12 |
protobuf |
— |
| protobuf |
affected |
Debian:13 |
protobuf |
— |
| protobuf |
affected |
Debian:14 |
protobuf |
— |
Open SourcePoC exploitHIGH2017-09-25
PYSEC-2017-65
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
PyPI |
protobuf |
— |
Open SourcePoC exploitHIGH2017-09-25
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
CVEs:CVE-2015-5237
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| protobuf |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2017-09-25
protobuf susceptible to buffer overflow
CVEs:CVE-2015-5237
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.protobuf:protobuf-parent |
affected |
Maven |
com.google.protobuf:protobuf-parent |
— |
| Google.Protobuf |
affected |
NuGet |
Google.Protobuf |
— |
| protobuf |
affected |
PyPI |
protobuf |
— |
| protobuf |
affected |
google |
google/protobuf |
— |
| protocolbuffers/protobuf |
affected |
github.com |
github.com/protocolbuffers/protobuf |
— |
Open SourcePoC exploitHIGH2017-09-25
PYSEC-2017-65
CVEs:CVE-2015-5237
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.google.protobuf:protobuf-parent |
affected |
Maven |
com.google.protobuf:protobuf-parent |
— |
| Google.Protobuf |
affected |
NuGet |
Google.Protobuf |
— |
| protobuf |
affected |
google |
google/protobuf |
— |
| protobuf |
affected |
PyPI |
protobuf |
— |
| protocolbuffers/protobuf |
affected |
github.com |
github.com/protocolbuffers/protobuf |
— |
Open SourcePoC exploitHIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thread and can be potentially freed in another.
CVEs:CVE-2017-11041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2017-09-06
CVEs:CVE-2017-11041
GooglePoC exploitMEDIUM2017-09-14
CVEs:CVE-2017-0783
Open SourcePoC exploitHIGH2017-09-14
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.
CVEs:CVE-2017-0783
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%2017-09-28
chromium-browser - security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Debian:9 |
chromium-browser |
— |
Open SourceEPSS <= 49%CRITICAL2017-09-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceEPSS <= 49%CRITICAL2017-09-15
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceEPSS <= 49%HIGH2017-09-12
Red Hat Security Advisory: chromium-browser security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Red Hat:rhel_extras:6 |
chromium-browser |
— |
| chromium-browser-debuginfo |
affected |
Red Hat:rhel_extras:6 |
chromium-browser-debuginfo |
— |
GoogleEPSS <= 49%HIGH2017-09-06
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
CVEs:CVE-2017-5115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-5115
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-5116
GoogleEPSS <= 49%CRITICAL2017-09-06
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2017-5116
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-09-14
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
CVEs:CVE-2017-1002003
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| wp2android-turn-wp-site-into-android-app |
affected |
wp2android-turn-wp-site-into-android-app_project |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-09-14
CVEs:CVE-2017-1002003
Open SourceEPSS <= 49%HIGH2017-09-25
Red Hat Security Advisory: chromium-browser security update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser |
affected |
Red Hat:rhel_extras:6 |
chromium-browser |
— |
| chromium-browser-debuginfo |
affected |
Red Hat:rhel_extras:6 |
chromium-browser-debuginfo |
— |
Open SourceEPSS <= 49%2017-09-23
Security update for Chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
Open SourceEPSS <= 49%2017-09-23
Security update for Chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 12 SP2 |
chromium |
— |
GoogleEPSS <= 49%HIGH2017-09-22
CVEs:CVE-2017-5121
GoogleEPSS <= 49%CRITICAL2017-09-22
Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.
CVEs:CVE-2017-5121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-09-06
Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVEs:CVE-2017-5112
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-5112
GoogleEPSS <= 49%CRITICAL2017-09-14
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.
CVEs:CVE-2013-7429
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlemaps |
affected |
mapsplugin |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-09-14
CVEs:CVE-2013-7429
Open SourceEPSS <= 49%CRITICAL2017-09-14
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146237.
CVEs:CVE-2017-0782
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-14
CVEs:CVE-2017-0782
GoogleEPSS <= 49%HIGH2017-09-07
CVEs:CVE-2013-7428
GoogleEPSS <= 49%HIGH2017-09-07
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php.
CVEs:CVE-2013-7428
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlemaps |
affected |
mapsplugin |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-27
Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code via a crafted application.
CVEs:CVE-2015-1537
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-27
CVEs:CVE-2015-1537
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-5119
GoogleEPSS <= 49%HIGH2017-09-06
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2017-5119
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-5117
GoogleEPSS <= 49%HIGH2017-09-06
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2017-5117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-20
DEBIAN-CVE-2017-14623
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-go-ldap-ldap |
affected |
Debian:11 |
golang-github-go-ldap-ldap |
— |
| golang-github-go-ldap-ldap |
affected |
Debian:12 |
golang-github-go-ldap-ldap |
— |
| golang-github-go-ldap-ldap |
affected |
Debian:13 |
golang-github-go-ldap-ldap |
— |
| golang-github-go-ldap-ldap |
affected |
Debian:14 |
golang-github-go-ldap-ldap |
— |
Open SourceEPSS <= 49%HIGH2017-09-08
Red Hat Bug Fix Advisory: OpenShift Container Platform 3.6.1 bug fix and enhancement update
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| atomic-openshift |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift |
— |
| atomic-openshift-clients |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-clients |
— |
| atomic-openshift-clients-redistributable |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-clients-redistributable |
— |
| atomic-openshift-cluster-capacity |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-cluster-capacity |
— |
| atomic-openshift-docker-excluder |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-docker-excluder |
— |
| atomic-openshift-dockerregistry |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-dockerregistry |
— |
| atomic-openshift-excluder |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-excluder |
— |
| atomic-openshift-federation-services |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-federation-services |
— |
| atomic-openshift-master |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-master |
— |
| atomic-openshift-node |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-node |
— |
| atomic-openshift-pod |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-pod |
— |
| atomic-openshift-sdn-ovs |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-sdn-ovs |
— |
| atomic-openshift-service-catalog |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-service-catalog |
— |
| atomic-openshift-tests |
affected |
Red Hat:openshift:3.6::el7 |
atomic-openshift-tests |
— |
| fluentd |
affected |
Red Hat:openshift:3.6::el7 |
fluentd |
— |
| fluentd-doc |
affected |
Red Hat:openshift:3.6::el7 |
fluentd-doc |
— |
| jenkins-2-plugins |
affected |
Red Hat:openshift:3.6::el7 |
jenkins-2-plugins |
— |
| kibana |
affected |
Red Hat:openshift:3.6::el7 |
kibana |
— |
| kibana-debuginfo |
affected |
Red Hat:openshift:3.6::el7 |
kibana-debuginfo |
— |
| rubygem-cool.io |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-cool.io |
— |
| rubygem-cool.io-debuginfo |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-cool.io-debuginfo |
— |
| rubygem-cool.io-doc |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-cool.io-doc |
— |
| rubygem-excon |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-excon |
— |
| rubygem-excon-doc |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-excon-doc |
— |
| rubygem-faraday |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-faraday |
— |
| rubygem-faraday-doc |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-faraday-doc |
— |
| rubygem-fluent-plugin-kubernetes_metadata_filter |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-fluent-plugin-kubernetes_metadata_filter |
— |
| rubygem-fluent-plugin-kubernetes_metadata_filter-doc |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-fluent-plugin-kubernetes_metadata_filter-doc |
— |
| rubygem-fluent-plugin-viaq_data_model |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-fluent-plugin-viaq_data_model |
— |
| rubygem-fluent-plugin-viaq_data_model-doc |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-fluent-plugin-viaq_data_model-doc |
— |
| rubygem-i18n |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-i18n |
— |
| rubygem-i18n-doc |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-i18n-doc |
— |
| rubygem-systemd-journal |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-systemd-journal |
— |
| rubygem-systemd-journal-doc |
affected |
Red Hat:openshift:3.6::el7 |
rubygem-systemd-journal-doc |
— |
| tuned-profiles-atomic-openshift-node |
affected |
Red Hat:openshift:3.6::el7 |
tuned-profiles-atomic-openshift-node |
— |
GoogleEPSS <= 49%MEDIUM2017-09-27
CVEs:CVE-2014-9686
GoogleEPSS <= 49%MEDIUM2017-09-27
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists ...
CVEs:CVE-2014-9686
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| googlemaps |
affected |
mapsplugin |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0758
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492741.
CVEs:CVE-2017-0758
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237396.
CVEs:CVE-2017-0760
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0760
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0761
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38448381.
CVEs:CVE-2017-0761
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0764
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872015.
CVEs:CVE-2017-0764
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-22
CVEs:CVE-2017-5122
GoogleEPSS <= 49%HIGH2017-09-22
Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.
CVEs:CVE-2017-5122
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-14
CVEs:CVE-2017-1002100
Open SourceEPSS <= 49%MEDIUM2017-09-14
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to t...
CVEs:CVE-2017-1002100
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
kubernetes |
— |
— |
GoogleEPSS <= 49%CRITICAL2017-09-06
Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
CVEs:CVE-2017-5114
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-5114
GoogleEPSS <= 49%HIGH2017-09-06
Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2017-5113
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-5113
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-5111
GoogleEPSS <= 49%CRITICAL2017-09-06
A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
CVEs:CVE-2017-5111
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-07
CVEs:CVE-2015-4697
GoogleEPSS <= 49%HIGH2017-09-07
Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.
CVEs:CVE-2015-4697
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google_analyticator |
affected |
sumo |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.
CVEs:CVE-2017-9725
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-9725
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-5118
GoogleEPSS <= 49%MEDIUM2017-09-06
Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a c...
CVEs:CVE-2017-5118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted ...
CVEs:CVE-2017-5120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-5120
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0753
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android libraries (libgdx). Product: Android. Versions: 7.1.1, 7.1.2, 8.0. Android ID: A-62218744.
CVEs:CVE-2017-0753
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36006815.
CVEs:CVE-2017-0757
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0757
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36715268.
CVEs:CVE-2017-0759
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0759
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62214264.
CVEs:CVE-2017-0762
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0762
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62534693.
CVEs:CVE-2017-0763
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0763
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872863.
CVEs:CVE-2017-0765
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0765
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0766
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libjhead). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37776688.
CVEs:CVE-2017-0766
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34621073.
CVEs:CVE-2017-0756
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0756
GoogleEPSS <= 49%HIGH2017-09-27
CVEs:CVE-2015-1526
Open SourceEPSS <= 49%HIGH2017-09-27
The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.
CVEs:CVE-2015-1526
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-8278
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, while reading audio data from an unspecified driver, a buffer overflow or integer overflow could occur.
CVEs:CVE-2017-8278
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0778
Open SourceEPSS <= 49%HIGH2017-09-06
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.
CVEs:CVE-2017-0778
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0786
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37351060. References: B-V2017060101.
CVEs:CVE-2017-0786
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-10998
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is fully within the valid region. If the buffer length i...
CVEs:CVE-2017-10998
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-09-08
DEBIAN-CVE-2017-0752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android-framework-23 |
affected |
Debian:11 |
android-framework-23 |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.
CVEs:CVE-2017-0752
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0752
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memor...
CVEs:CVE-2017-10996
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-10996
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0794
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Versions: Android kernel. Android ID: A-35644812.
CVEs:CVE-2017-0794
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0798
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36100671. References: M-ALPS03365532.
CVEs:CVE-2017-0798
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0799
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.
CVEs:CVE-2017-0799
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0800
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-37683975. References: M-ALPS03302988.
CVEs:CVE-2017-0800
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0801
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.
CVEs:CVE-2017-0801
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the Android libraries (libminikin). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-32178311.
CVEs:CVE-2017-0755
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0755
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37536407.
CVEs:CVE-2017-0767
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0767
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0768
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62019992.
CVEs:CVE-2017-0768
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37662122.
CVEs:CVE-2017-0769
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0769
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0770
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38234812.
CVEs:CVE-2017-0770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36198473. References: M-ALPS03361480.
CVEs:CVE-2017-0795
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0795
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0796
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Android ID: A-62458865. References: M-ALPS03353884, M-ALPS03353886, M-ALPS03353887.
CVEs:CVE-2017-0796
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0797
Open SourceEPSS <= 49%HIGH2017-09-06
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.
CVEs:CVE-2017-0797
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-8247
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once. This would lead to get_pid being called more than once, however p...
CVEs:CVE-2017-8247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-8250
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overflow to buffer overflow (with a smaller buffer allocat...
CVEs:CVE-2017-8250
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.
CVEs:CVE-2017-0793
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0793
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, specifically the ION cache maintenance code is writing to a user supplied address.
CVEs:CVE-2017-9724
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-9724
Open SourceEPSS <= 49%HIGH2017-09-06
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.
CVEs:CVE-2017-0776
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-0776
Open SourceEPSS <= 49%HIGH2017-09-06
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.
CVEs:CVE-2017-0777
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-0777
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cmd & msm_isp_stats_update_cgc_override, 'stream_cfg_cmd->num_streams' is not checked, and could overflow the array stream_cfg_cmd->st...
CVEs:CVE-2017-8251
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-8251
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0802
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36232120. References: M-ALPS03384818.
CVEs:CVE-2017-0802
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0803
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36136137. References: M-ALPS03361477.
CVEs:CVE-2017-0803
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0804
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the MediaTek mmc driver. Product: Android. Versions: Android kernel. Android ID: A-36274676. References: M-ALPS03361487.
CVEs:CVE-2017-0804
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-10997
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.
CVEs:CVE-2017-10997
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.
CVEs:CVE-2017-10999
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-10999
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-11000
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.
CVEs:CVE-2017-11000
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%MEDIUM2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
CVEs:CVE-2017-11001
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-11001
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-11002
Open SourceEPSS <= 49%MEDIUM2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.
CVEs:CVE-2017-11002
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-11040
Open SourceEPSS <= 49%MEDIUM2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
CVEs:CVE-2017-11040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38340117.
CVEs:CVE-2017-0779
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-0779
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
CVEs:CVE-2017-8281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-8281
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-8277
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_dba_register_client, if the client registers failed, it would be freed. However the client was not removed from list. Use-after-free would occur when tr...
CVEs:CVE-2017-8277
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-9720
Open SourceEPSS <= 49%HIGH2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one error in a camera driver, an out-of-bounds read/write can occur.
CVEs:CVE-2017-9720
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37624243.
CVEs:CVE-2017-0771
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0771
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0772
Open SourceEPSS <= 49%HIGH2017-09-06
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38115076.
CVEs:CVE-2017-0772
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0773
Open SourceEPSS <= 49%HIGH2017-09-06
A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37615911.
CVEs:CVE-2017-0773
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-06
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62673844.
CVEs:CVE-2017-0774
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0774
Open SourceEPSS <= 49%HIGH2017-09-06
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673179.
CVEs:CVE-2017-0775
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0775
Open SourceEPSS <= 49%HIGH2017-09-06
A denial of service vulnerability in the Android runtime (android messenger). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37742976.
CVEs:CVE-2017-0780
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0780
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-9677
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks. If one thread is...
CVEs:CVE-2017-9677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow during the context...
CVEs:CVE-2017-8280
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-8280
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722970. References: B-V2017053104.
CVEs:CVE-2017-0787
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0787
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0788
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722328. References: B-V2017053103.
CVEs:CVE-2017-0788
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0789
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37685267. References: B-V2017053102.
CVEs:CVE-2017-0789
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37357704. References: B-V2017053101.
CVEs:CVE-2017-0790
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0790
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37306719. References: B-V2017052302.
CVEs:CVE-2017-0791
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0791
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-9676
Open SourceEPSS <= 49%CRITICAL2017-09-06
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock.
CVEs:CVE-2017-9676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-06
CVEs:CVE-2017-0784
Open SourceEPSS <= 49%CRITICAL2017-09-06
A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.
CVEs:CVE-2017-0784
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2017-09-15
Integer overflow in IAudioPolicyService.cpp in Android allows local users to gain privileges via a crafted application, aka Android Bug ID 19261727.
CVEs:CVE-2015-1527
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2017-09-15
CVEs:CVE-2015-1527
Open SourceEPSS <= 49%HIGH2017-09-06
A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.
CVEs:CVE-2017-0792
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2017-09-06
CVEs:CVE-2017-0792