Google Security Advisories · January 2018 — Google Security Advisories
218 advisories 112 CVEs 10 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-0802

Project ZeroExploitedCISA KEV listed2018-01-10

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

CVEs:CVE-2018-0802

Upstream advisory

CVE-2018-0802

GoogleExploitedCISA KEV listedHIGH2018-01-10

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerab...

CVEs:CVE-2018-0802

Affected products

ProductStatusVendorPackageEcosystem
office affected microsoft
office_compatibility_pack affected microsoft
word affected microsoft
Upstream advisory

CVE-2018-3810

GoogleExploitedCISA KEV listedCRITICAL2018-01-01

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages serve...

CVEs:CVE-2018-3810

Affected products

ProductStatusVendorPackageEcosystem
smart_google_code_inserter affected oturia
Upstream advisory

CVE-2018-3811

GoogleExploitedCISA KEV listedCRITICAL2018-01-01

SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did n...

CVEs:CVE-2018-3811

Affected products

ProductStatusVendorPackageEcosystem
smart_google_code_inserter affected oturia
Upstream advisory

DSA-4103-1

Open SourceExploitedVulnCheck KEV listed2018-01-31

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

CVE-2017-13216

Open SourceWeaponized exploitHIGH2018-01-03

In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges need...

CVEs:CVE-2017-13216

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13209

Open SourceWeaponized exploitHIGH2018-01-03

In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a l...

CVEs:CVE-2017-13209

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-20346

GoogleActive exploitation (sightings)CRITICAL2018-01-01

SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by lev...

CVEs:CVE-2018-20346

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
leap affected opensuse
linux affected redhat
sqlite affected sqlite
Upstream advisory

RHSA-2018:0242

Open SourcePoC exploitMEDIUM2018-01-30

Red Hat Security Advisory: erlang security update

Affected products

ProductStatusVendorPackageEcosystem
erlang affected Red Hat:openstack:12::el7 erlang
erlang-asn1 affected Red Hat:openstack:12::el7 erlang-asn1
erlang-compiler affected Red Hat:openstack:12::el7 erlang-compiler
erlang-cosEvent affected Red Hat:openstack:12::el7 erlang-cosEvent
erlang-cosEventDomain affected Red Hat:openstack:12::el7 erlang-cosEventDomain
erlang-cosFileTransfer affected Red Hat:openstack:12::el7 erlang-cosFileTransfer
erlang-cosNotification affected Red Hat:openstack:12::el7 erlang-cosNotification
erlang-cosProperty affected Red Hat:openstack:12::el7 erlang-cosProperty
erlang-cosTime affected Red Hat:openstack:12::el7 erlang-cosTime
erlang-cosTransactions affected Red Hat:openstack:12::el7 erlang-cosTransactions
erlang-crypto affected Red Hat:openstack:12::el7 erlang-crypto
erlang-debuginfo affected Red Hat:openstack:12::el7 erlang-debuginfo
erlang-diameter affected Red Hat:openstack:12::el7 erlang-diameter
erlang-edoc affected Red Hat:openstack:12::el7 erlang-edoc
erlang-eldap affected Red Hat:openstack:12::el7 erlang-eldap
erlang-erl_docgen affected Red Hat:openstack:12::el7 erlang-erl_docgen
erlang-erl_interface affected Red Hat:openstack:12::el7 erlang-erl_interface
erlang-erts affected Red Hat:openstack:12::el7 erlang-erts
erlang-eunit affected Red Hat:openstack:12::el7 erlang-eunit
erlang-hipe affected Red Hat:openstack:12::el7 erlang-hipe
erlang-ic affected Red Hat:openstack:12::el7 erlang-ic
erlang-inets affected Red Hat:openstack:12::el7 erlang-inets
erlang-kernel affected Red Hat:openstack:12::el7 erlang-kernel
erlang-mnesia affected Red Hat:openstack:12::el7 erlang-mnesia
erlang-odbc affected Red Hat:openstack:12::el7 erlang-odbc
erlang-orber affected Red Hat:openstack:12::el7 erlang-orber
erlang-ose affected Red Hat:openstack:12::el7 erlang-ose
erlang-os_mon affected Red Hat:openstack:12::el7 erlang-os_mon
erlang-otp_mibs affected Red Hat:openstack:12::el7 erlang-otp_mibs
erlang-parsetools affected Red Hat:openstack:12::el7 erlang-parsetools
erlang-percept affected Red Hat:openstack:12::el7 erlang-percept
erlang-public_key affected Red Hat:openstack:12::el7 erlang-public_key
erlang-runtime_tools affected Red Hat:openstack:12::el7 erlang-runtime_tools
erlang-sasl affected Red Hat:openstack:12::el7 erlang-sasl
erlang-snmp affected Red Hat:openstack:12::el7 erlang-snmp
erlang-ssh affected Red Hat:openstack:12::el7 erlang-ssh
erlang-ssl affected Red Hat:openstack:12::el7 erlang-ssl
erlang-stdlib affected Red Hat:openstack:12::el7 erlang-stdlib
erlang-syntax_tools affected Red Hat:openstack:12::el7 erlang-syntax_tools
erlang-tools affected Red Hat:openstack:12::el7 erlang-tools
erlang-xmerl affected Red Hat:openstack:12::el7 erlang-xmerl
Upstream advisory

CVE-2017-13208

Open SourcePoC exploitHIGH2018-01-03

In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User...

CVEs:CVE-2017-13208

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13177

Open SourcePoC exploitHIGH2018-01-03

In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versi...

CVEs:CVE-2017-13177

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13178

Open SourcePoC exploitHIGH2018-01-03

In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails. This could lead to remote code execution as a privileged process with no additional execution privileg...

CVEs:CVE-2017-13178

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13197

Open SourcePoC exploitHIGH2018-01-03

In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2017-13197

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13176

Open SourcePoC exploitHIGH2018-01-03

In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges nee...

CVEs:CVE-2017-13176

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13225

Open SourcePoC exploitHIGH2018-01-03

In libMtkOmxVdec.so there is a possible heap buffer overflow. This could lead to a remote elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is needed for exploitation...

CVEs:CVE-2017-13225

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13203

Open SourcePoC exploitCRITICAL2018-01-03

An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63122634.

CVEs:CVE-2017-13203

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13204

Open SourcePoC exploitCRITICAL2018-01-03

An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64380237.

CVEs:CVE-2017-13204

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13222

Open SourcePoC exploitHIGH2018-01-03

An information disclosure vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-38159576.

CVEs:CVE-2017-13222

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13188

Open SourcePoC exploitCRITICAL2018-01-03

An information disclosure vulnerability in the Android media framework (aac). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65280786.

CVEs:CVE-2017-13188

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13205

Open SourcePoC exploitCRITICAL2018-01-03

An information disclosure vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64550583.

CVEs:CVE-2017-13205

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13202

Open SourcePoC exploitHIGH2018-01-03

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67647856.

CVEs:CVE-2017-13202

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13207

Open SourcePoC exploitHIGH2018-01-03

An information disclosure vulnerability in the Android media framework (stagefright mpeg4writer). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37564426.

CVEs:CVE-2017-13207

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11069

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, manipulation of SafeSwitch Image data can result in Heap overflow.

CVEs:CVE-2017-11069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15849

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a LayerStack can be destroyed in between Validate and Commit by the application resulting in a Use After Free condition.

CVEs:CVE-2017-15849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15850

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, userspace can read values from audio codec registers.

CVEs:CVE-2017-15850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14869

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FOTA partition, uninitialized data can be pushed to storage.

CVEs:CVE-2017-14869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13201

Open SourcePoC exploitHIGH2018-01-03

An information disclosure vulnerability in the Android media framework (mediadrm). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63982768.

CVEs:CVE-2017-13201

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13185

Open SourcePoC exploitCRITICAL2018-01-03

An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65123471.

CVEs:CVE-2017-13185

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13187

Open SourcePoC exploitCRITICAL2018-01-03

An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65034175.

CVEs:CVE-2017-13187

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13186

Open SourcePoC exploitHIGH2018-01-03

A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65735716.

CVEs:CVE-2017-13186

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11079

Open SourcePoC exploitCRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing sparse image, uninitialized heap memory can potentially be flashed due to the lack of validation of sparse image block head...

CVEs:CVE-2017-11079

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13200

Open SourcePoC exploitHIGH2018-01-03

An information disclosure vulnerability in the Android media framework (av) related to id3 unsynchronization. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63100526.

CVEs:CVE-2017-13200

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11066

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing ubi image an uninitialized memory could be accessed.

CVEs:CVE-2017-11066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14870

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating the recovery message for eMMC devices, 1088 bytes of stack memory can potentially be leaked.

CVEs:CVE-2017-14870

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14879

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, by calling an IPA ioctl and searching for routing/filer/hdr rule handle from ipa_idr pointer using ipa_idr_find() function, the wrong struct...

CVEs:CVE-2017-14879

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13210

Open SourcePoC exploitHIGH2018-01-03

In CameraDeviceClient::submitRequestList of CameraDeviceClient.cpp, there is an out-of-bounds write if metadataSize is too small. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execu...

CVEs:CVE-2017-13210

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13217

Open SourcePoC exploitHIGH2018-01-03

In DisplayFtmItem in the bootloader, there is an out-of-bounds write due to reading a string without verifying that it's null-terminated. This could lead to a secure boot bypass and a local elevation of privilege enabling code execution as a privileged...

CVEs:CVE-2017-13217

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9689

Open SourcePoC exploitCRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a specially-crafted HDMI CEC message can be used to cause stack memory corruption.

CVEs:CVE-2017-9689

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13213

Open SourcePoC exploitCRITICAL2018-01-03

An elevation of privilege vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-63374465. References: B-V2017081501.

CVEs:CVE-2017-13213

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9705

Open SourcePoC exploitCRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, concurrent rx notifications and read() operations in the G-Link PKT driver can result in a double free condition due to missing locking resu...

CVEs:CVE-2017-9705

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15848

Open SourcePoC exploitCRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the fastrpc kernel driver, a buffer overflow vulnerability from userspace may potentially exist.

CVEs:CVE-2017-15848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14873

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the pp_pgc_get_config() graphics driver function, a kernel memory overwrite can potentially occur.

CVEs:CVE-2017-14873

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11080

Open SourcePoC exploitCRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a user supplied sparse image, a buffer overflow vulnerability could occur if the sparse header block size is equal to 42949...

CVEs:CVE-2017-11080

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11081

Open SourcePoC exploitCRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a potential buffer overflow vulnerability in hdd_parse_setrmcenable_command and hdd_parse_setrmcactionperiod_command APIs as buffer...

CVEs:CVE-2017-11081

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15847

Open SourcePoC exploitHIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the SPCom kernel driver, a race condition exists when creating a channel.

CVEs:CVE-2017-15847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2018:0313-1

Open SourceCoalition ESS 30-63%CRITICAL2018-01-31

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
chromium affected SUSE:Package Hub 12 SP2 chromium
re2 affected SUSE:Package Hub 12 SP2 re2
re2 affected SUSE:Package Hub 12 re2
Upstream advisory

CVE-2018-6031

GoogleCoalition ESS 30-63%CRITICAL2018-01-25

Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2018-6031

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6034

GoogleCoalition ESS < 30%HIGH2018-01-25

Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-6034

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6043

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient data validation in External Protocol Handler in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially execute arbitrary programs on user machine via a crafted HTML page.

CVEs:CVE-2018-6043

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6036

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Insufficient data validation in V8 in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user data via a crafted HTML page.

CVEs:CVE-2018-6036

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6037

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.

CVEs:CVE-2018-6037

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6038

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-6038

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6045

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.

CVEs:CVE-2018-6045

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6035

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.

CVEs:CVE-2018-6035

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6033

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient data validation in Downloads in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted Chrome Extension.

CVEs:CVE-2018-6033

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6049

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.

CVEs:CVE-2018-6049

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6047

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user redirect URL via a crafted HTML page.

CVEs:CVE-2018-6047

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6054

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.

CVEs:CVE-2018-6054

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6032

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6032

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6040

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security policy via a crafted HTML page.

CVEs:CVE-2018-6040

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6052

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.

CVEs:CVE-2018-6052

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6050

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-6050

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6041

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-6041

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6048

GoogleCoalition ESS < 30%CRITICAL2018-01-25

Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak referrer information via a crafted HTML page.

CVEs:CVE-2018-6048

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6051

GoogleCoalition ESS < 30%CRITICAL2018-01-25

XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.

CVEs:CVE-2018-6051

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6042

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-6042

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6039

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.

CVEs:CVE-2018-6039

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6046

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.

CVEs:CVE-2018-6046

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6053

GoogleCoalition ESS < 30%MEDIUM2018-01-25

Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.

CVEs:CVE-2018-6053

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

MGASA-2018-0089

Open SourceEPSS <= 49%CRITICAL2018-01-21

Updated golang packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:6 golang
Upstream advisory

CVE-2015-1290

GoogleEPSS <= 49%HIGH2018-01-09

The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted web site.

CVEs:CVE-2015-1290

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
leap affected opensuse
qt affected qt
Upstream advisory

CVE-2017-13179

Open SourceEPSS <= 49%HIGH2018-01-03

In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free. Both ps_codec_obj and ps_create_op->s_ivd_create_op_t.pv_handle point to the same memory and ps_codec_obj could...

CVEs:CVE-2017-13179

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13193

Open SourceEPSS <= 49%HIGH2018-01-03

In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the same sps being fed in over and over. This could lead to a remote denial of service of a critical system process with no additional e...

CVEs:CVE-2017-13193

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13196

Open SourceEPSS <= 49%HIGH2018-01-03

In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could lead to memory leaks. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User int...

CVEs:CVE-2017-13196

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13199

Open SourceEPSS <= 49%HIGH2018-01-03

In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException later on. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. Us...

CVEs:CVE-2017-13199

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13211

Open SourceEPSS <= 49%HIGH2018-01-03

In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received. This could lead to a remote denial of service of a critical system process with no additional executi...

CVEs:CVE-2017-13211

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13214

Open SourceEPSS <= 49%HIGH2018-01-03

In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product...

CVEs:CVE-2017-13214

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2017-15133

Open SourceEPSS <= 49%HIGH2018-01-29

DEBIAN-CVE-2017-15133

Affected products

ProductStatusVendorPackageEcosystem
golang-github-miekg-dns affected Debian:12 golang-github-miekg-dns
golang-github-miekg-dns affected Debian:11 golang-github-miekg-dns
golang-github-miekg-dns affected Debian:13 golang-github-miekg-dns
golang-github-miekg-dns affected Debian:14 golang-github-miekg-dns
Upstream advisory

CVE-2017-13194

Open SourceEPSS <= 49%HIGH2018-01-03

A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.

CVEs:CVE-2017-13194

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

CVE-2017-0855

Open SourceEPSS <= 49%HIGH2018-01-03

In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution pr...

CVEs:CVE-2017-0855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13191

Open SourceEPSS <= 49%HIGH2018-01-03

In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is...

CVEs:CVE-2017-13191

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13192

Open SourceEPSS <= 49%HIGH2018-01-03

In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an infinite loop. This could lead to a remote denial of service of a critical system process with no additional execu...

CVEs:CVE-2017-13192

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13195

Open SourceEPSS <= 49%HIGH2018-01-03

In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead to negative indexes which could lead to an infinite loop. This could lead to a remote denial of service of a critical system process...

CVEs:CVE-2017-13195

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-1000498

Open SourceEPSS <= 49%HIGH2018-01-03

Android SVG vulnerable to XML External Entity (XXE)

CVEs:CVE-2017-1000498

Affected products

ProductStatusVendorPackageEcosystem
com.caverock:androidsvg affected Maven com.caverock:androidsvg
Upstream advisory

CVE-2017-1000498

Open SourceEPSS <= 49%CRITICAL2018-01-03

AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

CVEs:CVE-2017-1000498

Affected products

ProductStatusVendorPackageEcosystem
androidsvg affected androidsvg_project
Upstream advisory

CVE-2017-11010

Open SourceEPSS <= 49%HIGH2018-01-03

In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 650/52, SD 835, access control left a configuration space unprotected.

CVEs:CVE-2017-11010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14906

Open SourceEPSS <= 49%HIGH2018-01-03

In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.

CVEs:CVE-2017-14906

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13206

Open SourceEPSS <= 49%HIGH2018-01-03

An information disclosure vulnerability in the Android media framework (aacdec). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65025048.

CVEs:CVE-2017-13206

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13198

Open SourceEPSS <= 49%HIGH2018-01-03

A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68399117.

CVEs:CVE-2017-13198

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9712

Open SourceEPSS <= 49%HIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, if userspace provides a too-large IE length in wlan_hdd_cfg80211_set_ie, a buffer over-read occurs.

CVEs:CVE-2017-9712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13219

Open SourceEPSS <= 49%HIGH2018-01-03

A denial of service vulnerability in the Upstream kernel synaptics touchscreen controller. Product: Android. Versions: Android kernel. Android ID: A-62800865.

CVEs:CVE-2017-13219

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-1000460

GoogleEPSS <= 49%MEDIUM2018-01-03

In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

CVEs:CVE-2017-1000460

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
ffmpeg affected ffmpeg
libav affected libav
Upstream advisory

CVE-2017-13189

Open SourceEPSS <= 49%HIGH2018-01-03

A vulnerability in the Android media framework (libavc) related to handling dec_hdl memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68300072.

CVEs:CVE-2017-13189

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13190

Open SourceEPSS <= 49%HIGH2018-01-03

A vulnerability in the Android media framework (libhevc) related to handling ps_codec_obj memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68299873.

CVEs:CVE-2017-13190

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0846

Open SourceEPSS <= 49%HIGH2018-01-03

An information disclosure vulnerability in the Android framework (clipboardservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64934810.

CVEs:CVE-2017-0846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-7952

Open SourceEPSS <= 49%CRITICAL2018-01-12

The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.

CVEs:CVE-2014-7952

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13215

Open SourceEPSS <= 49%CRITICAL2018-01-03

A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.

CVEs:CVE-2017-13215

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-17860

Open SourceEPSS <= 49%MEDIUM2018-01-18

In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetooth address of target device and paired user's smartp...

CVEs:CVE-2017-17860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13220

Open SourceEPSS <= 49%CRITICAL2018-01-03

An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.

CVEs:CVE-2017-13220

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13218

Open SourceEPSS <= 49%HIGH2018-01-03

Access to CNTVCT_EL0 in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear could be used for side channel attacks and this could lead to local information disclosure with no additional execution privileges needed in FSM9055, I...

CVEs:CVE-2017-13218

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13184

Open SourceEPSS <= 49%HIGH2018-01-03

In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyncInjector. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges nee...

CVEs:CVE-2017-13184

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13181

Open SourceEPSS <= 49%HIGH2018-01-03

In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer. This could lead to an local elevation of privilege enabling code execution as a privileged process with no additional exe...

CVEs:CVE-2017-13181

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13182

Open SourceEPSS <= 49%HIGH2018-01-03

In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution ...

CVEs:CVE-2017-13182

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-0869

Open SourceEPSS <= 49%HIGH2018-01-03

NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elevation of privilege enabling code execution as a privileged process. This issue is rated as high. Version: N/A. Android ID: A-3777615...

CVEs:CVE-2017-0869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13180

Open SourceEPSS <= 49%HIGH2018-01-03

In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing. This could lead to a local ele...

CVEs:CVE-2017-13180

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13221

Open SourceEPSS <= 49%CRITICAL2018-01-03

An elevation of privilege vulnerability in the Upstream kernel wifi driver. Product: Android. Versions: Android kernel. Android ID: A-64709938.

CVEs:CVE-2017-13221

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13212

Open SourceEPSS <= 49%CRITICAL2018-01-03

An elevation of privilege vulnerability in the Android system (systemui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187985.

CVEs:CVE-2017-13212

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15845

Open SourceEPSS <= 49%CRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an invalid input of firmware size (negative value) from user space can potentially lead to the memory leak or buffer overflow during the WLA...

CVEs:CVE-2017-15845

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13183

Open SourceEPSS <= 49%HIGH2018-01-03

In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free due to a race condition if the user frees the buffer while it's being used in another thread. This could lead to a local elevation of privilege enablin...

CVEs:CVE-2017-13183

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11003

Open SourceEPSS <= 49%HIGH2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating a firmware image, data is read from flash into RAM without checking that the data fits into allotted RAM size.

CVEs:CVE-2017-11003

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13226

Open SourceEPSS <= 49%CRITICAL2018-01-03

An elevation of privilege vulnerability in the MediaTek mtk. Product: Android. Versions: Android kernel. Android ID: A-32591194. References: M-ALPS03149184.

CVEs:CVE-2017-13226

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11072

Open SourceEPSS <= 49%CRITICAL2018-01-03

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while calculating CRC for GPT header fields with partition entries greater than 16384 buffer overflow occurs.

CVEs:CVE-2017-11072

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.