CVE-2018-6065
CVEs:CVE-2018-6065
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2018-6065
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-6065
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
| mi6_browser | affected | mi | — | — |
CVEs:CVE-2017-13262
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2017-13262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...
CVEs:CVE-2017-13260
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13260
CVEs:CVE-2017-13261
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2017-13261
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...
CVEs:CVE-2017-13258
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13258
CVEs:CVE-2018-6064
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-6064
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploit...
CVEs:CVE-2017-13253
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13253
Red Hat Security Advisory: erlang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| erlang | affected | Red Hat:openstack:9::el7 | erlang | — |
| erlang-asn1 | affected | Red Hat:openstack:9::el7 | erlang-asn1 | — |
| erlang-compiler | affected | Red Hat:openstack:9::el7 | erlang-compiler | — |
| erlang-cosEvent | affected | Red Hat:openstack:9::el7 | erlang-cosEvent | — |
| erlang-cosEventDomain | affected | Red Hat:openstack:9::el7 | erlang-cosEventDomain | — |
| erlang-cosFileTransfer | affected | Red Hat:openstack:9::el7 | erlang-cosFileTransfer | — |
| erlang-cosNotification | affected | Red Hat:openstack:9::el7 | erlang-cosNotification | — |
| erlang-cosProperty | affected | Red Hat:openstack:9::el7 | erlang-cosProperty | — |
| erlang-cosTime | affected | Red Hat:openstack:9::el7 | erlang-cosTime | — |
| erlang-cosTransactions | affected | Red Hat:openstack:9::el7 | erlang-cosTransactions | — |
| erlang-crypto | affected | Red Hat:openstack:9::el7 | erlang-crypto | — |
| erlang-debuginfo | affected | Red Hat:openstack:9::el7 | erlang-debuginfo | — |
| erlang-diameter | affected | Red Hat:openstack:9::el7 | erlang-diameter | — |
| erlang-edoc | affected | Red Hat:openstack:9::el7 | erlang-edoc | — |
| erlang-eldap | affected | Red Hat:openstack:9::el7 | erlang-eldap | — |
| erlang-erl_docgen | affected | Red Hat:openstack:9::el7 | erlang-erl_docgen | — |
| erlang-erl_interface | affected | Red Hat:openstack:9::el7 | erlang-erl_interface | — |
| erlang-erts | affected | Red Hat:openstack:9::el7 | erlang-erts | — |
| erlang-eunit | affected | Red Hat:openstack:9::el7 | erlang-eunit | — |
| erlang-hipe | affected | Red Hat:openstack:9::el7 | erlang-hipe | — |
| erlang-ic | affected | Red Hat:openstack:9::el7 | erlang-ic | — |
| erlang-inets | affected | Red Hat:openstack:9::el7 | erlang-inets | — |
| erlang-kernel | affected | Red Hat:openstack:9::el7 | erlang-kernel | — |
| erlang-mnesia | affected | Red Hat:openstack:9::el7 | erlang-mnesia | — |
| erlang-odbc | affected | Red Hat:openstack:9::el7 | erlang-odbc | — |
| erlang-orber | affected | Red Hat:openstack:9::el7 | erlang-orber | — |
| erlang-ose | affected | Red Hat:openstack:9::el7 | erlang-ose | — |
| erlang-os_mon | affected | Red Hat:openstack:9::el7 | erlang-os_mon | — |
| erlang-otp_mibs | affected | Red Hat:openstack:9::el7 | erlang-otp_mibs | — |
| erlang-parsetools | affected | Red Hat:openstack:9::el7 | erlang-parsetools | — |
| erlang-percept | affected | Red Hat:openstack:9::el7 | erlang-percept | — |
| erlang-public_key | affected | Red Hat:openstack:9::el7 | erlang-public_key | — |
| erlang-runtime_tools | affected | Red Hat:openstack:9::el7 | erlang-runtime_tools | — |
| erlang-sasl | affected | Red Hat:openstack:9::el7 | erlang-sasl | — |
| erlang-snmp | affected | Red Hat:openstack:9::el7 | erlang-snmp | — |
| erlang-ssh | affected | Red Hat:openstack:9::el7 | erlang-ssh | — |
| erlang-ssl | affected | Red Hat:openstack:9::el7 | erlang-ssl | — |
| erlang-stdlib | affected | Red Hat:openstack:9::el7 | erlang-stdlib | — |
| erlang-syntax_tools | affected | Red Hat:openstack:9::el7 | erlang-syntax_tools | — |
| erlang-tools | affected | Red Hat:openstack:9::el7 | erlang-tools | — |
| erlang-xmerl | affected | Red Hat:openstack:9::el7 | erlang-xmerl | — |
DEBIAN-CVE-2017-1002101
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
CVEs:CVE-2017-1002101
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outsid...
CVEs:CVE-2017-1002101
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in install_locat...
CVEs:CVE-2018-1000073
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rubygems | affected | rubygems | — | — |
RubyGems Link Following vulnerability
CVEs:CVE-2018-1000073
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Infinite Loop vulnerability
CVEs:CVE-2018-1000075
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerabilit...
CVEs:CVE-2018-1000075
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| rubygems | affected | rubygems | — | — |
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Input Validation vulnerability in ruby ge...
CVEs:CVE-2018-1000077
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| rubygems | affected | rubygems | — | — |
RubyGems Improper Input Validation vulnerability
CVEs:CVE-2018-1000077
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems Improper Verification of Cryptographic Signature vulnerability
CVEs:CVE-2018-1000076
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature v...
CVEs:CVE-2018-1000076
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| rubygems | affected | rubygems | — | — |
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in...
CVEs:CVE-2018-1000074
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rubygems | affected | rubygems | — | — |
RubyGems Deserialization of Untrusted Data vulnerability
CVEs:CVE-2018-1000074
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2018-6066
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6066
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installat...
CVEs:CVE-2018-1000079
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rubygems | affected | rubygems | — | — |
RubyGems Path Traversal vulnerability
CVEs:CVE-2018-1000079
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem se...
CVEs:CVE-2018-1000078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| debian_linux | affected | debian | — | — |
| rubygems | affected | rubygems | — | — |
RubyGems Cross-site Scripting vulnerability
CVEs:CVE-2018-1000078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jruby:jruby-stdlib | affected | Maven | org.jruby:jruby-stdlib | — |
| rubygems-update | affected | RubyGems | rubygems-update | — |
DEBIAN-CVE-2017-1002102
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | Debian:12 | kubernetes | — |
| kubernetes | affected | Debian:11 | kubernetes | — |
| kubernetes | affected | Debian:13 | kubernetes | — |
| kubernetes | affected | Debian:14 | kubernetes | — |
Kubernetes arbitrary file overwrite
CVEs:CVE-2017-1002102
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are runn...
CVEs:CVE-2017-1002102
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | kubernetes | — | — |
CVEs:CVE-2017-18059
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id in wma_scan_event_callback(), which is received from firmware, leads to potential out of bounds memory...
CVEs:CVE-2017-18059
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2018-6061
A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-6061
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6060
Use after free in WebAudio in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-6060
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
CVEs:CVE-2018-6073
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6073
CVEs:CVE-2018-6079
Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2018-6079
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6069
Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2018-6069
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6062
Heap overflow write in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
CVEs:CVE-2018-6062
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.
CVEs:CVE-2018-6083
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6083
Incorrect use of mojo::WrapSharedMemoryHandle in Mojo in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.
CVEs:CVE-2018-6063
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6063
Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2018-6067
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6067
CVEs:CVE-2018-6077
Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVEs:CVE-2018-6077
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.
CVEs:CVE-2018-6074
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6074
CVEs:CVE-2018-6057
Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.
CVEs:CVE-2018-6057
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
CVEs:CVE-2018-6075
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6075
An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2018-6071
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6071
An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVEs:CVE-2018-6072
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6072
Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
CVEs:CVE-2018-6082
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6082
CVEs:CVE-2018-6080
Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .
CVEs:CVE-2018-6080
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6078
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVEs:CVE-2018-6078
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
CVEs:CVE-2018-6076
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6076
CVEs:CVE-2018-6068
Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2018-6068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6081
XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
CVEs:CVE-2018-6081
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| linux_desktop | affected | redhat | — | — |
| linux_server | affected | redhat | — | — |
| linux_workstation | affected | redhat | — | — |
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
CVEs:CVE-2018-6070
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_server | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
CVEs:CVE-2018-6070
CVEs:CVE-2018-3560
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Double Free vulnerability exists in Audio Driver while opening a sound compression device.
CVEs:CVE-2018-3560
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in diag_ioctl_lsm_deinit() leads to a Use After Free condition.
CVEs:CVE-2018-3561
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2018-3561
CVEs:CVE-2017-18067
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation while processing an encrypted authentication management frame in lim_send_auth_mgmt_frame() leads to buffer overflow.
CVEs:CVE-2017-18067
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2016-5179
Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.
CVEs:CVE-2016-5179
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome_os | affected | — | — |
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...
CVEs:CVE-2017-13266
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13266
CVEs:CVE-2017-13272
In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Prod...
CVEs:CVE-2017-13272
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.
CVEs:CVE-2014-4959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2014-4959
CVEs:CVE-2017-15815
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a potential buffer overflow can happen when processing any 802.11 MGMT frames like Auth frame in limProcessAuthFrame.
CVEs:CVE-2017-15815
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13259
In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to missing bounds checks. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2017-13259
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-14878
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to copy data has a size of only 8 bits and can be exceeded resulting in a denial of service.
CVEs:CVE-2017-14878
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13248
In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due to a missing bounds check. This could lead to an remote code execution with no additional execution privileges needed. User interaction is needed for exp...
CVEs:CVE-2017-13248
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In impeg2d_api_set_display_frame of impeg2d_api_main.c, there is an out of bound write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. ...
CVEs:CVE-2017-13249
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13249
In ih264d_fmt_conv_420sp_to_420p of ih264d_utils.c, there is an out of bound write due to a missing out of bounds check because of a multiplication error. This could lead to an remote code execution with no additional execution privileges needed. User ...
CVEs:CVE-2017-13250
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13250
CVEs:CVE-2017-14882
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor_specific(), a comparison is performed with the incom...
CVEs:CVE-2017-14882
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Cross-site Scripting in wicket-jquery-ui
CVEs:CVE-2017-15719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | affected | Maven | com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent | — |
In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.
CVEs:CVE-2017-15719
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| wicket-jquery-ui | affected | wicket-jquery-ui_project | — | — |
CVEs:CVE-2016-10393
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a clip with large size values, integer arithmetic overflows, and allocated buffer size will be less than intended buffer siz...
CVEs:CVE-2016-10393
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In bta_pan_data_buf_ind_cback of bta_pan_act.cc there is a use after free that can result in an out of bounds read of memory allocated via malloc. This could lead to information disclosure with no additional execution privileges needed. User interactio...
CVEs:CVE-2017-13257
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13257
In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-18, if the value param_buf->num_debug_register received from the FW command buffer is close to max of uint32, then the ...
CVEs:CVE-2017-14883
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-14883
Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs
CVEs:CVE-2018-1000109
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| org.jenkins-ci.plugins:google-play-android-publisher | affected | Maven | org.jenkins-ci.plugins:google-play-android-publisher | — |
An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.
CVEs:CVE-2018-1000109
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google-play-android-publisher | affected | jenkins | — | — |
In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Produc...
CVEs:CVE-2017-13255
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13255
In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2017-13256
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13256
In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer alloca...
CVEs:CVE-2017-17766
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-17766
CVEs:CVE-2017-14876
In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter params->entries[i].vfe_intf comes from userspace without any bounds check which could potentially result in a kernel out-of-bounds write.
CVEs:CVE-2017-14876
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-14877
While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL commands there is no mutex lock of allocated memory. If one thread sends an ioctl cmd IPA_IOC_QUERY_RT_TBL_INDEX while another sends an i...
CVEs:CVE-2017-14877
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-14881
While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-13, a use-after-free condition may potentially occur.
CVEs:CVE-2017-14881
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18069
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper message length calculation in oem_cmd_handler() while processing a WLAN_NL_MSG_OEM netlink message leads to buffer overread.
CVEs:CVE-2017-18069
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when running multi threaded with no additional execution privileges needed. Use...
CVEs:CVE-2017-13251
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13251
In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input validation that results in a read from uninitialized memory. This could lead to local escalation of privilege with no additional execution privileges needed. ...
CVEs:CVE-2017-13252
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13252
CVEs:CVE-2017-14875
In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a heap overread vulnerability exists.
CVEs:CVE-2017-14875
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
While processing the QCA_NL80211_VENDOR_SUBCMD_SET_TXPOWER_SCALE_DECR_DB vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_TXPOWER_SCALE_DECR_DB contains fewer than 1 byte, in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-11...
CVEs:CVE-2017-15859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15859
CVEs:CVE-2017-18051
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for event->vdev_id in wma_rcpi_event_handler(), which is received from firmware, leads to potential out of bounds ...
CVEs:CVE-2017-18051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for cmpl_params->num_reports, param_buf->desc_ids and param_buf->status in wma_mgmt_tx_bundle_completion_handler()...
CVEs:CVE-2017-18052
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18052
CVEs:CVE-2017-18053
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for fix_param->vdev_id in wma_p2p_lo_event_handler(), which is received from firmware, leads to potential out of b...
CVEs:CVE-2017-18053
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18057
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id in wma_nlo_scan_cmp_evt_handler(), which is received from firmware, leads to potential out of bounds m...
CVEs:CVE-2017-18057
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for wow_buf_pkt_len in wma_wow_wakeup_host_event() which is received from firmware leads to potential out of bound...
CVEs:CVE-2017-18058
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18058
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for resp_event->vdev_id in wma_unified_bcntx_status_event_handler(), which is received from firmware, leads to pot...
CVEs:CVE-2017-18060
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18060
CVEs:CVE-2017-11087
libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of...
CVEs:CVE-2017-11087
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-14891
In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the stack can get leaked due to an uninitialized variable.
CVEs:CVE-2017-14891
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13254
A other vulnerability in the Android media framework (AACExtractor). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70239507.
CVEs:CVE-2017-13254
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13264
A other vulnerability in the Android media framework (Avcdec). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70294343.
CVEs:CVE-2017-13264
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69006799.
CVEs:CVE-2017-13271
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13271
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 8.0, 8.1. Android ID: A-69383160.
CVEs:CVE-2017-13263
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13263
A elevation of privilege vulnerability in the Android system (OTA updates). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-36232423.
CVEs:CVE-2017-13265
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13265
CVEs:CVE-2017-13270
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69474744.
CVEs:CVE-2017-13270
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-14885
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, wma_unified_link_peer_stats_event_handler function has a variable num_rates which represents the sum of all the peer_stats->num_rates. The c...
CVEs:CVE-2017-14885
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18064
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for p2p_noa_info in wma_send_bcn_buf_ll() which is received from firmware leads to potential buffer overflow.
CVEs:CVE-2017-18064
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18068
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper buffer length calculation in wma_roam_scan_filter() leads to buffer overflow.
CVEs:CVE-2017-18068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18063
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for nlo_event in wma_nlo_match_evt_handler(), which is received from firmware, leads to potential out of bound mem...
CVEs:CVE-2017-18063
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function wma_p2p_noa_event_handler(), there is no bound check on a value coming from firmware which can potentially lead to a buffer ...
CVEs:CVE-2017-15821
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15821
CVEs:CVE-2017-13268
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67058064.
CVEs:CVE-2017-13268
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68818034.
CVEs:CVE-2017-13269
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-13269
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to the lack of a range check on the array index into the WMI descriptor pool, arbitrary address execution may potentially occur in the p...
CVEs:CVE-2017-14889
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-14889
CVEs:CVE-2017-15855
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, the camera application triggers "user-memory-access" issue as the Camera CPP module Linux...
CVEs:CVE-2017-15855
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In spectral_create_samp_msg() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-11, some values from firmware are not properly validated potentially leading to a buffer overflow.
CVEs:CVE-2017-15823
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15823
CVEs:CVE-2017-14887
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of messages of type eWNI_SME_MODIFY_ADDITIONAL_IES, an integer overflow leading to heap buffer overflow may potentially oc...
CVEs:CVE-2017-14887
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper ch_list array index initialization in function sme_set_plm_request() causes potential buffer overflow.
CVEs:CVE-2017-15830
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15830
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vent->vdev_id in wma_action_frame_filter_mac_event_handler(), which is received from firmware, leads to arbitr...
CVEs:CVE-2017-18065
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18065
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for num_vdev_mac_entries in wma_pdev_hw_mode_transition_evt_handler(), which is received from firmware, leads to p...
CVEs:CVE-2017-18054
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18054
CVEs:CVE-2017-18055
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for wmi_event->num_vdev_mac_entries in wma_pdev_set_hw_mode_resp_evt_handler(), which is received from firmware, l...
CVEs:CVE-2017-18055
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, potential buffer overflow can happen when processing AOA measurement event from WIGIG firmware in wil_aoa_evt_meas().
CVEs:CVE-2017-18061
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18061
CVEs:CVE-2017-18062
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, potential buffer overflow can happen when processing UTF event in wma_process_utf_event().
CVEs:CVE-2017-18062
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-9723
The touchscreen driver synaptics_dsx in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-05, the size of a stack-allocated buffer can be set to a value which exceeds the size of the stack.
CVEs:CVE-2017-9723
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function wma_ndp_end_indication_event_handler(), there is no input validation check on a event_info value coming from firmware, which...
CVEs:CVE-2017-15831
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15831
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in msm_flash_subdev_do_ioctl of drivers/media/platform/msm/camera_v2/sensor/flash/msm_flash.c, there is a possible out of bounds read if fla...
CVEs:CVE-2017-15814
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15814
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev_id in wma_unified_bcntx_status_event_handler() which is received from firmware leads to potential out of ...
CVEs:CVE-2017-18056
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18056
CVEs:CVE-2017-14892
In the function msm_pcm_hw_params() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-19, the return value of q6asm_open_shared_io() is not checked properly potentially leading to a possible dangling pointer access.
CVEs:CVE-2017-14892
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In the video_ioctl2() function in the camera driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-16, an untrusted pointer dereference may potentially occur.
CVEs:CVE-2017-15846
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15846
Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.
CVEs:CVE-2017-15852
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15852
CVEs:CVE-2017-17771
In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-02-12, an array out of bounds can occur.
CVEs:CVE-2017-17771
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is an obsolete set/reset ssid hotlist API.
CVEs:CVE-2017-11074
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-11074
CVEs:CVE-2017-15833
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, untrusted pointer dereference in update_userspace_power() function in power leads to information exposure.
CVEs:CVE-2017-15833
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18050
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev_map in wma_tbttoffset_update_event_handler(), which is received from firmware, leads to potential buffer ...
CVEs:CVE-2017-18050
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper controls in MSM CORE leads to use memory after it is freed in msm_core_ioctl().
CVEs:CVE-2017-18066
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-18066
CVEs:CVE-2017-6283
NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.
CVEs:CVE-2017-6283
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| shield_tv_firmware | affected | nvidia | — | — |
CVEs:CVE-2017-6281
NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-66969318. Reference: N-CVE-2017-6281.
CVEs:CVE-2017-6281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
NVIDIA libnvomx contains a possible out of bounds write due to a missing bounds check which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-64893247. Reference: N-CVE-2017-6286.
CVEs:CVE-2017-6286
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-6286
CVEs:CVE-2017-6282
NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.
CVEs:CVE-2017-6282
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| shield_tv_firmware | affected | nvidia | — | — |
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.
CVEs:CVE-2017-17769
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-17769
CVEs:CVE-2017-6295
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is r...
CVEs:CVE-2017-6295
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| shield_tv_firmware | affected | nvidia | — | — |
CVEs:CVE-2017-11082
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in a firmware loading routine, a buffer overflow could potentially occur if multiple user space threads try to updat...
CVEs:CVE-2017-11082
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-6285
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-64893156. Reference: N-CVE-2017-6285.
CVEs:CVE-2017-6285
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-6287
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate.Product: Android. Version: N/A. Android: A-64893264. Reference: N-CVE-2017-6287.
CVEs:CVE-2017-6287
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-6288
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-65482562. Reference: N-CVE-2017-6288.
CVEs:CVE-2017-6288
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Due to a race condition in MDSS rotator in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-20, a double free vulnerability may potentially exist when two threads free the same perf structures.
CVEs:CVE-2017-15826
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15826
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, race condition in diag_dbgfs_read_dcistats(), while accessing diag_dbgfs_dci_data_index, causes potential heap overflow.
CVEs:CVE-2017-15834
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2017-15834
CVEs:CVE-2017-6296
NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.
CVEs:CVE-2017-6296
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| shield_tv_firmware | affected | nvidia | — | — |
CVEs:CVE-2017-6284
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive da...
CVEs:CVE-2017-6284
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| shield_tv_firmware | affected | nvidia | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.