Google Security Advisories · March 2018 — Google Security Advisories
257 advisories 130 CVEs 2 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-6065

GoogleExploitedCISA KEV listedCRITICAL2018-03-07

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6065

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
mi6_browser affected mi
Upstream advisory

CVE-2017-13262

Open SourceWeaponized exploitMEDIUM2018-03-06

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2017-13262

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13260

Open SourceWeaponized exploitHIGH2018-03-06

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...

CVEs:CVE-2017-13260

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13261

Open SourceWeaponized exploitHIGH2018-03-06

In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2017-13261

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13258

Open SourceWeaponized exploitHIGH2018-03-06

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...

CVEs:CVE-2017-13258

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6064

GoogleWeaponized exploitHIGH2018-03-07

Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6064

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2017-13253

Open SourceWeaponized exploitHIGH2018-03-06

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2017-13253

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

RHSA-2018:0528

Open SourcePoC exploitMEDIUM2018-03-15

Red Hat Security Advisory: erlang security update

Affected products

ProductStatusVendorPackageEcosystem
erlang affected Red Hat:openstack:9::el7 erlang
erlang-asn1 affected Red Hat:openstack:9::el7 erlang-asn1
erlang-compiler affected Red Hat:openstack:9::el7 erlang-compiler
erlang-cosEvent affected Red Hat:openstack:9::el7 erlang-cosEvent
erlang-cosEventDomain affected Red Hat:openstack:9::el7 erlang-cosEventDomain
erlang-cosFileTransfer affected Red Hat:openstack:9::el7 erlang-cosFileTransfer
erlang-cosNotification affected Red Hat:openstack:9::el7 erlang-cosNotification
erlang-cosProperty affected Red Hat:openstack:9::el7 erlang-cosProperty
erlang-cosTime affected Red Hat:openstack:9::el7 erlang-cosTime
erlang-cosTransactions affected Red Hat:openstack:9::el7 erlang-cosTransactions
erlang-crypto affected Red Hat:openstack:9::el7 erlang-crypto
erlang-debuginfo affected Red Hat:openstack:9::el7 erlang-debuginfo
erlang-diameter affected Red Hat:openstack:9::el7 erlang-diameter
erlang-edoc affected Red Hat:openstack:9::el7 erlang-edoc
erlang-eldap affected Red Hat:openstack:9::el7 erlang-eldap
erlang-erl_docgen affected Red Hat:openstack:9::el7 erlang-erl_docgen
erlang-erl_interface affected Red Hat:openstack:9::el7 erlang-erl_interface
erlang-erts affected Red Hat:openstack:9::el7 erlang-erts
erlang-eunit affected Red Hat:openstack:9::el7 erlang-eunit
erlang-hipe affected Red Hat:openstack:9::el7 erlang-hipe
erlang-ic affected Red Hat:openstack:9::el7 erlang-ic
erlang-inets affected Red Hat:openstack:9::el7 erlang-inets
erlang-kernel affected Red Hat:openstack:9::el7 erlang-kernel
erlang-mnesia affected Red Hat:openstack:9::el7 erlang-mnesia
erlang-odbc affected Red Hat:openstack:9::el7 erlang-odbc
erlang-orber affected Red Hat:openstack:9::el7 erlang-orber
erlang-ose affected Red Hat:openstack:9::el7 erlang-ose
erlang-os_mon affected Red Hat:openstack:9::el7 erlang-os_mon
erlang-otp_mibs affected Red Hat:openstack:9::el7 erlang-otp_mibs
erlang-parsetools affected Red Hat:openstack:9::el7 erlang-parsetools
erlang-percept affected Red Hat:openstack:9::el7 erlang-percept
erlang-public_key affected Red Hat:openstack:9::el7 erlang-public_key
erlang-runtime_tools affected Red Hat:openstack:9::el7 erlang-runtime_tools
erlang-sasl affected Red Hat:openstack:9::el7 erlang-sasl
erlang-snmp affected Red Hat:openstack:9::el7 erlang-snmp
erlang-ssh affected Red Hat:openstack:9::el7 erlang-ssh
erlang-ssl affected Red Hat:openstack:9::el7 erlang-ssl
erlang-stdlib affected Red Hat:openstack:9::el7 erlang-stdlib
erlang-syntax_tools affected Red Hat:openstack:9::el7 erlang-syntax_tools
erlang-tools affected Red Hat:openstack:9::el7 erlang-tools
erlang-xmerl affected Red Hat:openstack:9::el7 erlang-xmerl
Upstream advisory

DEBIAN-CVE-2017-1002101

Open SourcePoC exploitCRITICAL2018-03-13

DEBIAN-CVE-2017-1002101

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2017-1002101

Open SourcePoC exploitCRITICAL2018-03-13

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outsid...

CVEs:CVE-2017-1002101

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2018-1000073

GooglePoC exploitHIGH2018-03-13

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in install_locat...

CVEs:CVE-2018-1000073

Affected products

ProductStatusVendorPackageEcosystem
rubygems affected rubygems
Upstream advisory

CVE-2018-1000073

Open SourcePoC exploitHIGH2018-03-13

RubyGems Link Following vulnerability

CVEs:CVE-2018-1000073

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

CVE-2018-1000075

Open SourcePoC exploitHIGH2018-03-13

RubyGems Infinite Loop vulnerability

CVEs:CVE-2018-1000075

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

CVE-2018-1000075

GooglePoC exploitHIGH2018-03-13

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerabilit...

CVEs:CVE-2018-1000075

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
rubygems affected rubygems
Upstream advisory

CVE-2018-1000077

GooglePoC exploitMEDIUM2018-03-13

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Input Validation vulnerability in ruby ge...

CVEs:CVE-2018-1000077

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
rubygems affected rubygems
Upstream advisory

CVE-2018-1000077

Open SourcePoC exploitMEDIUM2018-03-13

RubyGems Improper Input Validation vulnerability

CVEs:CVE-2018-1000077

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

CVE-2018-1000076

Open SourcePoC exploitCRITICAL2018-03-13

RubyGems Improper Verification of Cryptographic Signature vulnerability

CVEs:CVE-2018-1000076

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

CVE-2018-1000076

GooglePoC exploitCRITICAL2018-03-13

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature v...

CVEs:CVE-2018-1000076

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
rubygems affected rubygems
Upstream advisory

CVE-2018-1000074

GooglePoC exploitHIGH2018-03-13

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in...

CVEs:CVE-2018-1000074

Affected products

ProductStatusVendorPackageEcosystem
rubygems affected rubygems
Upstream advisory

CVE-2018-1000074

Open SourcePoC exploitHIGH2018-03-13

RubyGems Deserialization of Untrusted Data vulnerability

CVEs:CVE-2018-1000074

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

CVE-2018-6066

GooglePoC exploitCRITICAL2018-03-07

Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6066

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-1000079

GooglePoC exploitMEDIUM2018-03-13

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installat...

CVEs:CVE-2018-1000079

Affected products

ProductStatusVendorPackageEcosystem
rubygems affected rubygems
Upstream advisory

CVE-2018-1000079

Open SourcePoC exploitMEDIUM2018-03-13

RubyGems Path Traversal vulnerability

CVEs:CVE-2018-1000079

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

CVE-2018-1000078

GooglePoC exploitHIGH2018-03-13

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem se...

CVEs:CVE-2018-1000078

Affected products

ProductStatusVendorPackageEcosystem
debian_linux affected debian
rubygems affected rubygems
Upstream advisory

CVE-2018-1000078

Open SourcePoC exploitMEDIUM2018-03-13

RubyGems Cross-site Scripting vulnerability

CVEs:CVE-2018-1000078

Affected products

ProductStatusVendorPackageEcosystem
org.jruby:jruby-stdlib affected Maven org.jruby:jruby-stdlib
rubygems-update affected RubyGems rubygems-update
Upstream advisory

DEBIAN-CVE-2017-1002102

Open SourcePoC exploitMEDIUM2018-03-13

DEBIAN-CVE-2017-1002102

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2017-1002102

Open SourcePoC exploitHIGH2018-03-13

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are runn...

CVEs:CVE-2017-1002102

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
Upstream advisory

CVE-2017-18059

Open SourcePoC exploitHIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id in wma_scan_event_callback(), which is received from firmware, leads to potential out of bounds memory...

CVEs:CVE-2017-18059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6061

GoogleCoalition ESS 30-63%HIGH2018-03-07

A race in the handling of SharedArrayBuffers in WebAssembly in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6061

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6060

GoogleCoalition ESS < 30%CRITICAL2018-03-07

Use after free in WebAudio in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6060

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6073

GoogleCoalition ESS < 30%CRITICAL2018-03-07

A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2018-6073

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6079

GoogleCoalition ESS < 30%MEDIUM2018-03-07

Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6079

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6069

GoogleCoalition ESS < 30%CRITICAL2018-03-07

Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-6069

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6062

GoogleCoalition ESS < 30%CRITICAL2018-03-07

Heap overflow write in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2018-6062

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6083

GoogleCoalition ESS < 30%HIGH2018-03-07

Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to access privileged APIs via a crafted HTML page.

CVEs:CVE-2018-6083

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6063

GoogleCoalition ESS < 30%HIGH2018-03-07

Incorrect use of mojo::WrapSharedMemoryHandle in Mojo in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2018-6063

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6067

GoogleCoalition ESS < 30%HIGH2018-03-07

Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6067

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6077

GoogleCoalition ESS < 30%MEDIUM2018-03-07

Displacement map filters being applied to cross-origin images in Blink SVG rendering in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6077

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6074

GoogleCoalition ESS < 30%HIGH2018-03-07

Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a crafted HTML page.

CVEs:CVE-2018-6074

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6057

GoogleCoalition ESS < 30%HIGH2018-03-07

Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.

CVEs:CVE-2018-6057

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6075

GoogleCoalition ESS < 30%MEDIUM2018-03-07

Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.

CVEs:CVE-2018-6075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6071

GoogleCoalition ESS < 30%CRITICAL2018-03-07

An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-6071

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6072

GoogleCoalition ESS < 30%CRITICAL2018-03-07

An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2018-6072

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6082

GoogleCoalition ESS < 30%MEDIUM2018-03-07

Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.

CVEs:CVE-2018-6082

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6080

GoogleCoalition ESS < 30%MEDIUM2018-03-07

Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .

CVEs:CVE-2018-6080

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6078

GoogleCoalition ESS < 30%MEDIUM2018-03-07

Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

CVEs:CVE-2018-6078

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6076

GoogleCoalition ESS < 30%CRITICAL2018-03-07

Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.

CVEs:CVE-2018-6076

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6068

GoogleCoalition ESS < 30%MEDIUM2018-03-07

Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-6068

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6081

GoogleCoalition ESS < 30%CRITICAL2018-03-07

XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.

CVEs:CVE-2018-6081

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
linux_desktop affected redhat
linux_server affected redhat
linux_workstation affected redhat
Upstream advisory

CVE-2018-6070

GoogleCoalition ESS < 30%CRITICAL2018-03-07

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVEs:CVE-2018-6070

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-3560

Open SourceCoalition ESS < 30%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Double Free vulnerability exists in Audio Driver while opening a sound compression device.

CVEs:CVE-2018-3560

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3561

Open SourceCoalition ESS < 30%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in diag_ioctl_lsm_deinit() leads to a Use After Free condition.

CVEs:CVE-2018-3561

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18067

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation while processing an encrypted authentication management frame in lim_send_auth_mgmt_frame() leads to buffer overflow.

CVEs:CVE-2017-18067

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5179

GoogleEPSS <= 49%HIGH2018-03-06

Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.

CVEs:CVE-2016-5179

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2017-13266

Open SourceEPSS <= 49%HIGH2018-03-06

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...

CVEs:CVE-2017-13266

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13272

Open SourceEPSS <= 49%HIGH2018-03-06

In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Prod...

CVEs:CVE-2017-13272

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-4959

Open SourceEPSS <= 49%CRITICAL2018-03-27

**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.

CVEs:CVE-2014-4959

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15815

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a potential buffer overflow can happen when processing any 802.11 MGMT frames like Auth frame in limProcessAuthFrame.

CVEs:CVE-2017-15815

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13259

Open SourceEPSS <= 49%HIGH2018-03-06

In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to missing bounds checks. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2017-13259

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14878

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to copy data has a size of only 8 bits and can be exceeded resulting in a denial of service.

CVEs:CVE-2017-14878

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13248

Open SourceEPSS <= 49%HIGH2018-03-06

In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due to a missing bounds check. This could lead to an remote code execution with no additional execution privileges needed. User interaction is needed for exp...

CVEs:CVE-2017-13248

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13249

Open SourceEPSS <= 49%HIGH2018-03-06

In impeg2d_api_set_display_frame of impeg2d_api_main.c, there is an out of bound write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. ...

CVEs:CVE-2017-13249

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13250

Open SourceEPSS <= 49%HIGH2018-03-06

In ih264d_fmt_conv_420sp_to_420p of ih264d_utils.c, there is an out of bound write due to a missing out of bounds check because of a multiplication error. This could lead to an remote code execution with no additional execution privileges needed. User ...

CVEs:CVE-2017-13250

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14882

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor_specific(), a comparison is performed with the incom...

CVEs:CVE-2017-14882

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15719

GoogleEPSS <= 49%MEDIUM2018-03-12

Cross-site Scripting in wicket-jquery-ui

CVEs:CVE-2017-15719

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent affected Maven com.googlecode.wicket-jquery-ui:wicket-jquery-ui-parent
Upstream advisory

CVE-2017-15719

GoogleEPSS <= 49%MEDIUM2018-03-12

In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.

CVEs:CVE-2017-15719

Affected products

ProductStatusVendorPackageEcosystem
wicket-jquery-ui affected wicket-jquery-ui_project
Upstream advisory

CVE-2016-10393

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a clip with large size values, integer arithmetic overflows, and allocated buffer size will be less than intended buffer siz...

CVEs:CVE-2016-10393

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13257

Open SourceEPSS <= 49%HIGH2018-03-06

In bta_pan_data_buf_ind_cback of bta_pan_act.cc there is a use after free that can result in an out of bounds read of memory allocated via malloc. This could lead to information disclosure with no additional execution privileges needed. User interactio...

CVEs:CVE-2017-13257

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14883

Open SourceEPSS <= 49%CRITICAL2018-03-30

In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-18, if the value param_buf->num_debug_register received from the FW command buffer is close to max of uint32, then the ...

CVEs:CVE-2017-14883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-1000109

Open SourceEPSS <= 49%MEDIUM2018-03-13

Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs

CVEs:CVE-2018-1000109

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-play-android-publisher affected Maven org.jenkins-ci.plugins:google-play-android-publisher
Upstream advisory

CVE-2018-1000109

Open SourceEPSS <= 49%MEDIUM2018-03-13

An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.

CVEs:CVE-2018-1000109

Affected products

ProductStatusVendorPackageEcosystem
google-play-android-publisher affected jenkins
Upstream advisory

CVE-2017-13255

Open SourceEPSS <= 49%HIGH2018-03-06

In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Produc...

CVEs:CVE-2017-13255

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13256

Open SourceEPSS <= 49%HIGH2018-03-06

In process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2017-13256

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-17766

Open SourceEPSS <= 49%CRITICAL2018-03-30

In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer alloca...

CVEs:CVE-2017-17766

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14876

Open SourceEPSS <= 49%CRITICAL2018-03-30

In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter params->entries[i].vfe_intf comes from userspace without any bounds check which could potentially result in a kernel out-of-bounds write.

CVEs:CVE-2017-14876

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14877

Open SourceEPSS <= 49%CRITICAL2018-03-30

While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL commands there is no mutex lock of allocated memory. If one thread sends an ioctl cmd IPA_IOC_QUERY_RT_TBL_INDEX while another sends an i...

CVEs:CVE-2017-14877

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14881

Open SourceEPSS <= 49%CRITICAL2018-03-30

While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-13, a use-after-free condition may potentially occur.

CVEs:CVE-2017-14881

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18069

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper message length calculation in oem_cmd_handler() while processing a WLAN_NL_MSG_OEM netlink message leads to buffer overread.

CVEs:CVE-2017-18069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13251

Open SourceEPSS <= 49%HIGH2018-03-06

In impeg2d_dec_pic_data_thread of impeg2d_dec_hdr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when running multi threaded with no additional execution privileges needed. Use...

CVEs:CVE-2017-13251

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13252

Open SourceEPSS <= 49%HIGH2018-03-06

In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input validation that results in a read from uninitialized memory. This could lead to local escalation of privilege with no additional execution privileges needed. ...

CVEs:CVE-2017-13252

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14875

Open SourceEPSS <= 49%HIGH2018-03-30

In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a heap overread vulnerability exists.

CVEs:CVE-2017-14875

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15859

Open SourceEPSS <= 49%HIGH2018-03-30

While processing the QCA_NL80211_VENDOR_SUBCMD_SET_TXPOWER_SCALE_DECR_DB vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_TXPOWER_SCALE_DECR_DB contains fewer than 1 byte, in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-11...

CVEs:CVE-2017-15859

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18051

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for event->vdev_id in wma_rcpi_event_handler(), which is received from firmware, leads to potential out of bounds ...

CVEs:CVE-2017-18051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18052

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for cmpl_params->num_reports, param_buf->desc_ids and param_buf->status in wma_mgmt_tx_bundle_completion_handler()...

CVEs:CVE-2017-18052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18053

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for fix_param->vdev_id in wma_p2p_lo_event_handler(), which is received from firmware, leads to potential out of b...

CVEs:CVE-2017-18053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18057

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id in wma_nlo_scan_cmp_evt_handler(), which is received from firmware, leads to potential out of bounds m...

CVEs:CVE-2017-18057

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18058

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for wow_buf_pkt_len in wma_wow_wakeup_host_event() which is received from firmware leads to potential out of bound...

CVEs:CVE-2017-18058

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18060

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for resp_event->vdev_id in wma_unified_bcntx_status_event_handler(), which is received from firmware, leads to pot...

CVEs:CVE-2017-18060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11087

Open SourceEPSS <= 49%HIGH2018-03-30

libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of...

CVEs:CVE-2017-11087

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14891

Open SourceEPSS <= 49%MEDIUM2018-03-30

In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the stack can get leaked due to an uninitialized variable.

CVEs:CVE-2017-14891

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13254

Open SourceEPSS <= 49%HIGH2018-03-06

A other vulnerability in the Android media framework (AACExtractor). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70239507.

CVEs:CVE-2017-13254

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13264

Open SourceEPSS <= 49%HIGH2018-03-06

A other vulnerability in the Android media framework (Avcdec). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70294343.

CVEs:CVE-2017-13264

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13271

Open SourceEPSS <= 49%CRITICAL2018-03-06

A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69006799.

CVEs:CVE-2017-13271

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13263

Open SourceEPSS <= 49%CRITICAL2018-03-06

A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 8.0, 8.1. Android ID: A-69383160.

CVEs:CVE-2017-13263

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13265

Open SourceEPSS <= 49%CRITICAL2018-03-06

A elevation of privilege vulnerability in the Android system (OTA updates). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-36232423.

CVEs:CVE-2017-13265

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13270

Open SourceEPSS <= 49%CRITICAL2018-03-06

A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69474744.

CVEs:CVE-2017-13270

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14885

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, wma_unified_link_peer_stats_event_handler function has a variable num_rates which represents the sum of all the peer_stats->num_rates. The c...

CVEs:CVE-2017-14885

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18064

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for p2p_noa_info in wma_send_bcn_buf_ll() which is received from firmware leads to potential buffer overflow.

CVEs:CVE-2017-18064

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18068

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper buffer length calculation in wma_roam_scan_filter() leads to buffer overflow.

CVEs:CVE-2017-18068

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18063

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for nlo_event in wma_nlo_match_evt_handler(), which is received from firmware, leads to potential out of bound mem...

CVEs:CVE-2017-18063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15821

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function wma_p2p_noa_event_handler(), there is no bound check on a value coming from firmware which can potentially lead to a buffer ...

CVEs:CVE-2017-15821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13268

Open SourceEPSS <= 49%HIGH2018-03-06

A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67058064.

CVEs:CVE-2017-13268

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13269

Open SourceEPSS <= 49%HIGH2018-03-06

A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68818034.

CVEs:CVE-2017-13269

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14889

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to the lack of a range check on the array index into the WMI descriptor pool, arbitrary address execution may potentially occur in the p...

CVEs:CVE-2017-14889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15855

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, the camera application triggers "user-memory-access" issue as the Camera CPP module Linux...

CVEs:CVE-2017-15855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15823

Open SourceEPSS <= 49%CRITICAL2018-03-30

In spectral_create_samp_msg() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-11, some values from firmware are not properly validated potentially leading to a buffer overflow.

CVEs:CVE-2017-15823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14887

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of messages of type eWNI_SME_MODIFY_ADDITIONAL_IES, an integer overflow leading to heap buffer overflow may potentially oc...

CVEs:CVE-2017-14887

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15830

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper ch_list array index initialization in function sme_set_plm_request() causes potential buffer overflow.

CVEs:CVE-2017-15830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18065

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vent->vdev_id in wma_action_frame_filter_mac_event_handler(), which is received from firmware, leads to arbitr...

CVEs:CVE-2017-18065

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18054

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for num_vdev_mac_entries in wma_pdev_hw_mode_transition_evt_handler(), which is received from firmware, leads to p...

CVEs:CVE-2017-18054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18055

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for wmi_event->num_vdev_mac_entries in wma_pdev_set_hw_mode_resp_evt_handler(), which is received from firmware, l...

CVEs:CVE-2017-18055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18061

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, potential buffer overflow can happen when processing AOA measurement event from WIGIG firmware in wil_aoa_evt_meas().

CVEs:CVE-2017-18061

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18062

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, potential buffer overflow can happen when processing UTF event in wma_process_utf_event().

CVEs:CVE-2017-18062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-9723

Open SourceEPSS <= 49%HIGH2018-03-30

The touchscreen driver synaptics_dsx in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-05, the size of a stack-allocated buffer can be set to a value which exceeds the size of the stack.

CVEs:CVE-2017-9723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15831

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function wma_ndp_end_indication_event_handler(), there is no input validation check on a event_info value coming from firmware, which...

CVEs:CVE-2017-15831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15814

Open SourceEPSS <= 49%MEDIUM2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in msm_flash_subdev_do_ioctl of drivers/media/platform/msm/camera_v2/sensor/flash/msm_flash.c, there is a possible out of bounds read if fla...

CVEs:CVE-2017-15814

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18056

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev_id in wma_unified_bcntx_status_event_handler() which is received from firmware leads to potential out of ...

CVEs:CVE-2017-18056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14892

Open SourceEPSS <= 49%HIGH2018-03-30

In the function msm_pcm_hw_params() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-19, the return value of q6asm_open_shared_io() is not checked properly potentially leading to a possible dangling pointer access.

CVEs:CVE-2017-14892

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15846

Open SourceEPSS <= 49%HIGH2018-03-30

In the video_ioctl2() function in the camera driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-16, an untrusted pointer dereference may potentially occur.

CVEs:CVE-2017-15846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15852

Open SourceEPSS <= 49%HIGH2018-03-30

Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.

CVEs:CVE-2017-15852

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-17771

Open SourceEPSS <= 49%HIGH2018-03-30

In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-02-12, an array out of bounds can occur.

CVEs:CVE-2017-17771

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-11074

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is an obsolete set/reset ssid hotlist API.

CVEs:CVE-2017-11074

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15833

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, untrusted pointer dereference in update_userspace_power() function in power leads to information exposure.

CVEs:CVE-2017-15833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18050

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev_map in wma_tbttoffset_update_event_handler(), which is received from firmware, leads to potential buffer ...

CVEs:CVE-2017-18050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18066

Open SourceEPSS <= 49%HIGH2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper controls in MSM CORE leads to use memory after it is freed in msm_core_ioctl().

CVEs:CVE-2017-18066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6283

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.

CVEs:CVE-2017-6283

Affected products

ProductStatusVendorPackageEcosystem
android affected google
shield_tv_firmware affected nvidia
Upstream advisory

CVE-2017-6281

Open SourceEPSS <= 49%CRITICAL2018-03-06

NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-66969318. Reference: N-CVE-2017-6281.

CVEs:CVE-2017-6281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6286

Open SourceEPSS <= 49%CRITICAL2018-03-06

NVIDIA libnvomx contains a possible out of bounds write due to a missing bounds check which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-64893247. Reference: N-CVE-2017-6286.

CVEs:CVE-2017-6286

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6282

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.

CVEs:CVE-2017-6282

Affected products

ProductStatusVendorPackageEcosystem
android affected google
shield_tv_firmware affected nvidia
Upstream advisory

CVE-2017-17769

Open SourceEPSS <= 49%HIGH2018-03-30

Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.

CVEs:CVE-2017-17769

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6295

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is r...

CVEs:CVE-2017-6295

Affected products

ProductStatusVendorPackageEcosystem
android affected google
shield_tv_firmware affected nvidia
Upstream advisory

CVE-2017-11082

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in a firmware loading routine, a buffer overflow could potentially occur if multiple user space threads try to updat...

CVEs:CVE-2017-11082

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6285

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-64893156. Reference: N-CVE-2017-6285.

CVEs:CVE-2017-6285

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6287

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate.Product: Android. Version: N/A. Android: A-64893264. Reference: N-CVE-2017-6287.

CVEs:CVE-2017-6287

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6288

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-65482562. Reference: N-CVE-2017-6288.

CVEs:CVE-2017-6288

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15826

Open SourceEPSS <= 49%CRITICAL2018-03-30

Due to a race condition in MDSS rotator in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-20, a double free vulnerability may potentially exist when two threads free the same perf structures.

CVEs:CVE-2017-15826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15834

Open SourceEPSS <= 49%CRITICAL2018-03-06

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, race condition in diag_dbgfs_read_dcistats(), while accessing diag_dbgfs_dci_data_index, causes potential heap overflow.

CVEs:CVE-2017-15834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6296

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.

CVEs:CVE-2017-6296

Affected products

ProductStatusVendorPackageEcosystem
android affected google
shield_tv_firmware affected nvidia
Upstream advisory

CVE-2017-6284

Open SourceEPSS <= 49%HIGH2018-03-06

NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive da...

CVEs:CVE-2017-6284

Affected products

ProductStatusVendorPackageEcosystem
android affected google
shield_tv_firmware affected nvidia
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.