Google Security Advisories · May 2018 — Google Security Advisories
181 advisories 90 CVEs 13 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 13 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-8174

GoogleExploitedCISA KEV listedCRITICAL2018-05-09

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve...

CVEs:CVE-2018-8174

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1607 affected microsoft
windows_10_1607 affected microsoft
windows_10_1703 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
Upstream advisory

CVE-2018-8174

Project ZeroExploitedCISA KEV listed2018-05-09

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVEs:CVE-2018-8174

Upstream advisory

CVE-2018-8120

Project ZeroExploitedCISA KEV listed2018-05-09

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

CVEs:CVE-2018-8120

Upstream advisory

CVE-2018-8120

GoogleExploitedCISA KEV listedCRITICAL2018-05-09

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This...

CVEs:CVE-2018-8120

Affected products

ProductStatusVendorPackageEcosystem
Windows affected Microsoft
windows_7 affected microsoft
windows_server_2008 affected microsoft
Upstream advisory

openSUSE-SU-2018:1175-1

Open SourceExploitedCISA KEV listedHIGH2018-05-27

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

openSUSE-SU-2018:1437-1

Open SourceExploitedCISA KEV listedHIGH2018-05-27

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP2 chromium
Upstream advisory

CVE-2018-4990

Project ZeroExploitedCISA KEV listed2018-05-14

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVEs:CVE-2018-4990

Upstream advisory

CVE-2018-4990

GoogleExploitedCISA KEV listedCRITICAL2018-05-14

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVEs:CVE-2018-4990

Affected products

ProductStatusVendorPackageEcosystem
acrobat_dc affected adobe
acrobat_reader_dc affected adobe
Upstream advisory

CVE-2017-13315

Open SourceExploitedVulnCheck KEV listedHIGH2018-05-09

In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execut...

CVEs:CVE-2017-13315

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6126

GoogleWeaponized exploitHIGH2018-05-30

A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2018-6126

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6130

GoogleWeaponized exploitMEDIUM2018-05-30

Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2018-6130

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6129

GoogleWeaponized exploitMEDIUM2018-05-30

Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2018-6129

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2017-13322

Open SourceActive exploitation (sightings)CRITICAL2018-05-09

In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local denial of service with no additional execution privileges needed. User ...

CVEs:CVE-2017-13322

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13317

Open SourceActive exploitation (sightings)MEDIUM2018-05-09

In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed...

CVEs:CVE-2017-13317

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13318

Open SourceActive exploitation (sightings)HIGH2018-05-09

In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2017-13318

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2018-0238

Open SourceEPSS 49-79%CRITICAL2018-05-16

Updated golang packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
golang affected Mageia:6 golang
Upstream advisory

CVE-2018-6140

GoogleCoalition ESS < 30%HIGH2018-05-30

Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

CVEs:CVE-2018-6140

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6120

GoogleCoalition ESS < 30%CRITICAL2018-05-11

An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.

CVEs:CVE-2018-6120

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6139

GoogleCoalition ESS < 30%CRITICAL2018-05-30

Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

CVEs:CVE-2018-6139

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6124

GoogleCoalition ESS < 30%HIGH2018-05-30

Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

CVEs:CVE-2018-6124

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6137

GoogleCoalition ESS < 30%MEDIUM2018-05-30

CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6137

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6123

GoogleCoalition ESS < 30%CRITICAL2018-05-30

A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6123

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6127

GoogleCoalition ESS < 30%CRITICAL2018-05-30

Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2018-6127

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6141

GoogleCoalition ESS < 30%HIGH2018-05-30

Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-6141

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6143

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-6143

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6144

GoogleCoalition ESS < 30%HIGH2018-05-30

Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file.

CVEs:CVE-2018-6144

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6118

GoogleCoalition ESS < 30%CRITICAL2018-05-27

A double-eviction in the Incognito mode cache that lead to a user-after-free in cache in Google Chrome prior to 66.0.3359.139 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2018-6118

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6135

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2018-6135

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6133

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6133

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6131

GoogleCoalition ESS < 30%HIGH2018-05-30

Object lifecycle issue in WebAssembly in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6131

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6128

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2018-6128

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6132

GoogleCoalition ESS < 30%HIGH2018-05-30

Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.

CVEs:CVE-2018-6132

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6121

GoogleCoalition ESS < 30%CRITICAL2018-05-11

Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a crafted HTML page.

CVEs:CVE-2018-6121

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6134

GoogleCoalition ESS < 30%HIGH2018-05-30

Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page.

CVEs:CVE-2018-6134

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6142

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Array bounds check failure in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

CVEs:CVE-2018-6142

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6136

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Missing type check in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-6136

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6122

GoogleCoalition ESS < 30%HIGH2018-05-11

Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6122

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6138

GoogleCoalition ESS < 30%CRITICAL2018-05-30

Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVEs:CVE-2018-6138

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6125

GoogleCoalition ESS < 30%CRITICAL2018-05-30

Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.

CVEs:CVE-2018-6125

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6145

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Insufficient data validation in HTML parser in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2018-6145

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-3578

Open SourceCoalition ESS < 30%HIGH2018-05-09

Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading to a heap buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-3578

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5850

Open SourceCoalition ESS < 30%HIGH2018-05-09

In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Ke...

CVEs:CVE-2018-5850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5846

Open SourceCoalition ESS < 30%HIGH2018-05-09

A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_DEL/IPA_IOC_NOTIFY_WAN_EMBMS_CONNECTED are called in all Android releases from CAF (Android for MSM, ...

CVEs:CVE-2018-5846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6147

GoogleCoalition ESS < 30%MEDIUM2018-05-30

Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.

CVEs:CVE-2018-6147

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-5840

Open SourceCoalition ESS < 30%HIGH2018-05-09

Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-5840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5841

Open SourceCoalition ESS < 30%HIGH2018-05-09

dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using...

CVEs:CVE-2018-5841

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3565

Open SourceCoalition ESS < 30%HIGH2018-05-09

While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overflow can occur.

CVEs:CVE-2018-3565

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3580

Open SourceCoalition ESS < 30%HIGH2018-05-09

Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-3580

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5848

Open SourceCoalition ESS < 30%CRITICAL2018-05-09

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS f...

CVEs:CVE-2018-5848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
virtualization_host affected redhat
Upstream advisory

CVE-2018-6246

Open SourceCoalition ESS < 30%HIGH2018-05-09

In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosur...

CVEs:CVE-2018-6246

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3562

Open SourceCoalition ESS < 30%HIGH2018-05-09

Buffer over -read can occur while processing a FILS authentication frame in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-3562

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5845

Open SourceCoalition ESS < 30%CRITICAL2018-05-09

A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-5845

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5842

Open SourceCoalition ESS < 30%HIGH2018-05-09

An arbitrary address write can occur if a compromised WLAN firmware sends incorrect data to WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-5842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5843

Open SourceCoalition ESS < 30%HIGH2018-05-09

In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, there is no upper bound check on the value event->num_chains_valid received from firmware which ...

CVEs:CVE-2018-5843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5851

Open SourceCoalition ESS < 30%HIGH2018-05-09

Buffer over flow can occur while processing a HTT_T2H_MSG_TYPE_TX_COMPL_IND message with an out-of-range num_msdus value in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-5851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3571

Open SourceCoalition ESS < 30%CRITICAL2018-05-09

In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations

CVEs:CVE-2018-3571

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3572

Open SourceCoalition ESS < 30%HIGH2018-05-09

While processing a DSP buffer in an audio driver's event handler, an index of a buffer is not checked before accessing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-3572

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3576

Open SourceCoalition ESS < 30%HIGH2018-05-09

improper validation of array index in WiFi driver function sapInterferenceRssiCount() leads to array out-of-bounds access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-3576

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3581

Open SourceCoalition ESS < 30%HIGH2018-05-09

In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overwrite can occur if the vdev_id received from firmware is larger than max_bssid.

CVEs:CVE-2018-3581

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5844

Open SourceCoalition ESS < 30%HIGH2018-05-09

In the video driver function set_output_buffers(), binfo can be accessed after being freed in a failure scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-5844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5847

Open SourceCoalition ESS < 30%CRITICAL2018-05-09

Early or late retirement of rotation requests can result in a Use After Free condition in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-5847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3582

Open SourceCoalition ESS < 30%CRITICAL2018-05-09

Buffer overflow can occur due to improper input validation in multiple WMA event handler functions in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2018-3582

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3579

Open SourceCoalition ESS < 30%MEDIUM2018-05-09

In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, event->num_entries_in_page is a value received from firmware that is not properly validated which can lead to a buffer over-read

CVEs:CVE-2018-3579

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5853

Open SourceCoalition ESS < 30%CRITICAL2018-05-09

A race condition exists in a driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-05-05 potentially leading to a use-after-free condition.

CVEs:CVE-2018-5853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6254

Open SourceCoalition ESS < 30%HIGH2018-05-09

In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-643...

CVEs:CVE-2018-6254

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5849

Open SourceCoalition ESS < 30%CRITICAL2018-05-09

Due to a race condition in the QTEECOM driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, when more than one HLOS client loads the same TA, a Use After Free condition can occur.

CVEs:CVE-2018-5849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-17689

GoogleEPSS <= 49%MEDIUM2018-05-14

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVEs:CVE-2017-17689

Affected products

ProductStatusVendorPackageEcosystem
airmail affected bloop
emclient affected emclient
evolution affected gnome
gmail affected google
horde_imp affected horde
kmail affected kde
mail affected apple
maildroid affected flipdogsolutions
mailmate affected freron
nine affected 9folders
notes affected ibm
outlook affected microsoft
postbox affected postbox-inc
r2mail2 affected r2mail2
the_bat affected ritlabs
thunderbird affected mozilla
trojita affected kde
Upstream advisory

CVE-2018-1000400

GoogleEPSS <= 49%HIGH2018-05-18

Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not ...

CVEs:CVE-2018-1000400

Affected products

ProductStatusVendorPackageEcosystem
cri-o affected kubernetes
Upstream advisory

CVE-2018-1000173

GoogleEPSS <= 49%MEDIUM2018-05-08

A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

CVEs:CVE-2018-1000173

Affected products

ProductStatusVendorPackageEcosystem
google_login affected jenkins
Upstream advisory

CVE-2018-1000173

GoogleEPSS <= 49%MEDIUM2018-05-08

Jenkins Google Login Plugin Session Fixation vulnerability

CVEs:CVE-2018-1000173

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

CVE-2018-0579

GoogleEPSS <= 49%CRITICAL2018-05-14

Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVEs:CVE-2018-0579

Affected products

ProductStatusVendorPackageEcosystem
open_graph_for_facebook\,_google\+_and_twitter_card_tags affected webdados
Upstream advisory

CVE-2018-1000174

GoogleEPSS <= 49%MEDIUM2018-05-08

Jenkins Google Login Plugin Open Redirect vulnerability

CVEs:CVE-2018-1000174

Affected products

ProductStatusVendorPackageEcosystem
org.jenkins-ci.plugins:google-login affected Maven org.jenkins-ci.plugins:google-login
Upstream advisory

CVE-2018-1000174

GoogleEPSS <= 49%MEDIUM2018-05-08

An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.

CVEs:CVE-2018-1000174

Affected products

ProductStatusVendorPackageEcosystem
google_login affected jenkins
Upstream advisory

CVE-2018-0577

GoogleEPSS <= 49%CRITICAL2018-05-14

Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVEs:CVE-2018-0577

Affected products

ProductStatusVendorPackageEcosystem
wp_google_map affected flippercode
Upstream advisory

CVE-2016-10524

Open SourceEPSS <= 49%HIGH2018-05-31

Denial of Service and Content Injection in i18n-node-angular

CVEs:CVE-2016-10524

Affected products

ProductStatusVendorPackageEcosystem
i18n-node-angular affected npm i18n-node-angular
Upstream advisory

CVE-2016-10524

Open SourceEPSS <= 49%HIGH2018-05-31

Denial of Service and Content Injection in i18n-node-angular

CVEs:CVE-2016-10524

Affected products

ProductStatusVendorPackageEcosystem
i18n-node-angular affected npm i18n-node-angular
Upstream advisory

CVE-2016-10524

Open SourceEPSS <= 49%CRITICAL2018-05-31

i18n-node-angular is a module used to interact between i18n and angular without using additional resources. A REST API endpoint that is used for development in i18n-node-angular before 1.4.0 was not disabled in production environments a malicious user ...

CVEs:CVE-2016-10524

Affected products

ProductStatusVendorPackageEcosystem
i18n-node-angular affected i18n-node-angular_project
Upstream advisory

CVE-2018-10229

GoogleEPSS <= 49%MEDIUM2018-05-04

A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.

CVEs:CVE-2018-10229

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
firefox affected mozilla
nexus_5 affected lg
Upstream advisory

CVE-2017-13319

Open SourceEPSS <= 49%HIGH2018-05-09

In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution privileges neede...

CVEs:CVE-2017-13319

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13313

Open SourceEPSS <= 49%HIGH2018-05-09

In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges...

CVEs:CVE-2017-13313

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13320

Open SourceEPSS <= 49%MEDIUM2018-05-09

In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2017-13320

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18154

Open SourceEPSS <= 49%HIGH2018-05-09

A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2017-18154

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6289

Open SourceEPSS <= 49%CRITICAL2018-05-09

In Android before the 2018-05-05 security patch level, NVIDIA Trusted Execution Environment (TEE) contains a memory corruption (due to unusual root cause) vulnerability, which if run within the speculative execution of the TEE, may lead to local escala...

CVEs:CVE-2017-6289

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15842

Open SourceEPSS <= 49%HIGH2018-05-09

Buffer might get used after it gets freed due to unlocking the mutex before freeing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2017-15842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15857

Open SourceEPSS <= 49%HIGH2018-05-09

In the camera driver, an out-of-bounds access can occur due to an error in copying region params from user space in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2017-15857

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18070

Open SourceEPSS <= 49%HIGH2018-05-09

In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in all...

CVEs:CVE-2017-18070

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15854

Open SourceEPSS <= 49%CRITICAL2018-05-09

The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma_radio_chan_stats_event_handler() for the derived length len leading to a subsequent buffer overflow in all Android releases from CA...

CVEs:CVE-2017-15854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-6293

Open SourceEPSS <= 49%HIGH2018-05-09

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. ...

CVEs:CVE-2017-6293

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15843

Open SourceEPSS <= 49%CRITICAL2018-05-09

Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVEs:CVE-2017-15843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13321

Open SourceEPSS <= 49%MEDIUM2018-05-09

In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional executio...

CVEs:CVE-2017-13321

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13323

Open SourceEPSS <= 49%HIGH2018-05-09

In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2017-13323

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13316

Open SourceEPSS <= 49%HIGH2018-05-09

In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...

CVEs:CVE-2017-13316

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13309

Open SourceEPSS <= 49%MEDIUM2018-05-09

In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2017-13309

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13310

Open SourceEPSS <= 49%HIGH2018-05-09

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional exe...

CVEs:CVE-2017-13310

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13314

Open SourceEPSS <= 49%HIGH2018-05-09

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are suppos...

CVEs:CVE-2017-13314

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13311

Open SourceEPSS <= 49%HIGH2018-05-09

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no addition...

CVEs:CVE-2017-13311

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-13312

Open SourceEPSS <= 49%HIGH2018-05-09

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional executi...

CVEs:CVE-2017-13312

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.