Google Security Advisories · July 2018 — Google Security Advisories
202 advisories 102 CVEs 2 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-5383

Open SourceExploitedVulnCheck KEV listedHIGH2018-07-23

Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate ...

CVEs:CVE-2018-5383

Affected products

ProductStatusVendorPackageEcosystem
android affected google
iphone_os affected apple
mac_os_x affected apple
wl18xx_bluetooth_service_pack affected ti
Upstream advisory

CVE-2018-5865

Open SourceWeaponized exploitMEDIUM2018-07-03

While processing a debug log event from firmware in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, an integer underflow and/or buffer over-read can occur.

CVEs:CVE-2018-5865

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

GHSA-4rvg-955w-h68q

Open SourcePoC exploitHIGH2018-07-26

Path Traversal in angular-http-server

Affected products

ProductStatusVendorPackageEcosystem
angular-http-server affected npm angular-http-server
Upstream advisory

GHSA-4rvg-955w-h68q

Open SourcePoC exploitHIGH2018-07-26

Path Traversal in angular-http-server

Affected products

ProductStatusVendorPackageEcosystem
angular-http-server affected npm angular-http-server
Upstream advisory

CVE-2018-9411

Open SourcePoC exploitHIGH2018-07-03

In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9411

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5873

Open SourcePoC exploitCRITICAL2018-07-03

An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kern...

CVEs:CVE-2018-5873

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2018-9365

Open SourcePoC exploitCRITICAL2018-07-03

In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2018-9365

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3569

Open SourcePoC exploitHIGH2018-07-06

A buffer over-read can occur during a fast initial link setup (FILS) connection in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVEs:CVE-2018-3569

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18158

Open SourcePoC exploitCRITICAL2018-07-06

Possible buffer overflows and array out of bounds accesses in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05 while flashing images.

CVEs:CVE-2017-18158

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5831

Open SourcePoC exploitCRITICAL2018-07-06

In the KGSL driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a reference counting error can lead to a Use After Free condition.

CVEs:CVE-2018-5831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DSA-4256-1

Open SourceCoalition ESS < 30%2018-07-26

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

CVE-2018-6174

GoogleCoalition ESS < 30%CRITICAL2018-07-25

Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVEs:CVE-2018-6174

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6164

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6164

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6162

GoogleCoalition ESS < 30%HIGH2018-07-25

Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6162

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6153

GoogleCoalition ESS < 30%HIGH2018-07-25

A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.

CVEs:CVE-2018-6153

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6170

GoogleCoalition ESS < 30%HIGH2018-07-25

A bad cast in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVEs:CVE-2018-6170

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6165

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-6165

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6166

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6166

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6163

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6163

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6167

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6167

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6172

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6172

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6173

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6173

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6175

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVEs:CVE-2018-6175

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6169

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.

CVEs:CVE-2018-6169

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6158

GoogleCoalition ESS < 30%HIGH2018-07-25

A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6158

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6152

GoogleCoalition ESS < 30%CRITICAL2018-07-25

The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potent...

CVEs:CVE-2018-6152

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6151

GoogleCoalition ESS < 30%HIGH2018-07-25

Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension.

CVEs:CVE-2018-6151

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6179

GoogleCoalition ESS < 30%CRITICAL2018-07-25

Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a craft...

CVEs:CVE-2018-6179

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-5855

Open SourceCoalition ESS < 30%HIGH2018-07-03

While padding or shrinking a nested wmi packet in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a buffer over-read can potentially occur.

CVEs:CVE-2018-5855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6160

GoogleCoalition ESS < 30%MEDIUM2018-07-25

JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-6160

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6178

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.

CVEs:CVE-2018-6178

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-6177

GoogleCoalition ESS < 30%HIGH2018-07-25

Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6177

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6154

GoogleCoalition ESS < 30%HIGH2018-07-25

Insufficient data validation in WebGL in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-6154

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6161

GoogleCoalition ESS < 30%CRITICAL2018-07-25

Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2018-6161

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6150

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-6150

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6156

GoogleCoalition ESS < 30%HIGH2018-07-25

Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

CVEs:CVE-2018-6156

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
ubuntu_linux affected canonical
Upstream advisory

CVE-2018-3577

Open SourceCoalition ESS < 30%CRITICAL2018-07-06

While processing fragments, when the fragment count becomes very large, an integer overflow leading to a buffer overflow can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security pa...

CVEs:CVE-2018-3577

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6157

GoogleCoalition ESS < 30%HIGH2018-07-25

Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

CVEs:CVE-2018-6157

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6159

GoogleCoalition ESS < 30%CRITICAL2018-07-25

Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2018-6159

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-6168

GoogleCoalition ESS < 30%HIGH2018-07-25

Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2018-6168

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MGASA-2018-0308

Open SourceCoalition ESS < 30%CRITICAL2018-07-11

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:6 chromium-browser-stable
Upstream advisory

CVE-2018-6155

GoogleCoalition ESS < 30%MEDIUM2018-07-25

Incorrect handling of frames in the VP8 parser in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

CVEs:CVE-2018-6155

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-3586

Open SourceCoalition ESS < 30%HIGH2018-07-03

An integer overflow to buffer overflow vulnerability exists in the ADSPRPC heap manager in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

CVEs:CVE-2018-3586

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5886

Open SourceCoalition ESS < 30%HIGH2018-07-06

A pointer in an ADSPRPC command is not properly validated in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android), which can lead to kernel memory being accessed.

CVEs:CVE-2018-5886

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5897

Open SourceCoalition ESS < 30%HIGH2018-07-06

While reading the data from buffer in dci_process_ctrl_status() there can be buffer over-read problem if the len is not checked correctly in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before secu...

CVEs:CVE-2018-5897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6176

GoogleCoalition ESS < 30%CRITICAL2018-07-25

Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.

CVEs:CVE-2018-6176

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-5872

Open SourceCoalition ESS < 30%HIGH2018-07-03

While parsing over-the-air information elements in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, the use of an out-of-range pointer offset can occur.

CVEs:CVE-2018-5872

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9516

Open SourceCoalition ESS < 30%HIGH2018-07-23

In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2018-9516

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
ubuntu_linux affected canonical
Upstream advisory

CVE-2018-9430

Open SourceCoalition ESS < 30%CRITICAL2018-07-03

In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6171

GoogleCoalition ESS < 30%CRITICAL2018-07-25

Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.

CVEs:CVE-2018-6171

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-9419

Open SourceCoalition ESS < 30%HIGH2018-07-03

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2018-9419

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9418

Open SourceCoalition ESS < 30%CRITICAL2018-07-03

In handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2018-9418

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9385

Open SourceCoalition ESS < 30%HIGH2018-07-24

In driver_override_store of bus.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Prod...

CVEs:CVE-2018-9385

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9433

Open SourceCoalition ESS < 30%CRITICAL2018-07-03

In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9433

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9415

Open SourceCoalition ESS < 30%HIGH2018-07-03

In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2018-9415

Affected products

ProductStatusVendorPackageEcosystem
android affected google
ubuntu_linux affected canonical
Upstream advisory

CVE-2018-9426

Open SourceCoalition ESS < 30%HIGH2018-07-03

In  RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect implementation could cause weak RSA key pairs being generated. This could lead to crypto vulnerability with no additional execution privileges needed. User int...

CVEs:CVE-2018-9426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9429

Open SourceCoalition ESS < 30%MEDIUM2018-07-03

In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9422

Open SourceCoalition ESS < 30%HIGH2018-07-03

In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android k...

CVEs:CVE-2018-9422

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

CVE-2018-9413

Open SourceCoalition ESS < 30%HIGH2018-07-03

In handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9413

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5862

Open SourceCoalition ESS < 30%HIGH2018-07-03

In __wlan_hdd_cfg80211_vendor_scan() in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, when SCAN_SSIDS and QCA_WLAN_VENDOR_ATTR_SCAN_FREQUENCIES are parsed...

CVEs:CVE-2018-5862

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5889

Open SourceCoalition ESS < 30%CRITICAL2018-07-06

While processing a compressed kernel image, a buffer overflow can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVEs:CVE-2018-5889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5858

Open SourceCoalition ESS < 30%HIGH2018-07-03

In the audio debugfs in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, out of bounds access can occur.

CVEs:CVE-2018-5858

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3587

Open SourceCoalition ESS < 30%CRITICAL2018-07-06

In a firmware memory dump feature in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android), a Use After Free condition can occur.

CVEs:CVE-2018-3587

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3564

Open SourceCoalition ESS < 30%CRITICAL2018-07-06

In the FastRPC driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a Use After Free condition can occur when mapping on the remote processor fails.

CVEs:CVE-2018-3564

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5893

Open SourceCoalition ESS < 30%HIGH2018-07-06

While processing a message from firmware in htt_t2h_msg_handler_fast() in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a buffer overwrite can occur.

CVEs:CVE-2018-5893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5836

Open SourceCoalition ESS < 30%MEDIUM2018-07-06

In wma_nan_rsp_event_handler() in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, the data_len value is received from firmware and not properly validated which ...

CVEs:CVE-2018-5836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5864

Open SourceCoalition ESS < 30%HIGH2018-07-03

While processing a WMI_APFIND event in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a buffer over-read and information leak can potentially occur.

CVEs:CVE-2018-5864

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5907

Open SourceCoalition ESS < 30%CRITICAL2018-07-03

Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

CVEs:CVE-2018-5907

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3597

Open SourceCoalition ESS < 30%HIGH2018-07-06

In the ADSP RPC driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, an arbitrary kernel write can occur.

CVEs:CVE-2018-3597

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5890

Open SourceCoalition ESS < 30%HIGH2018-07-06

If the fdt_totalsize is reported as 0 for the current device tree, it bypasses an error check for a valid device tree in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 201...

CVEs:CVE-2018-5890

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5887

Open SourceCoalition ESS < 30%HIGH2018-07-06

While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVEs:CVE-2018-5887

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5888

Open SourceCoalition ESS < 30%HIGH2018-07-06

While processing the system path, an out of bounds access can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVEs:CVE-2018-5888

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5899

Open SourceCoalition ESS < 30%CRITICAL2018-07-06

In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, whenever TDLS connection is setup, we are freeing the netbuf in ol_tx_completion_handler and after that, we a...

CVEs:CVE-2018-5899

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3570

Open SourceCoalition ESS < 30%HIGH2018-07-03

In the cpuidle driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, the list_for_each macro was not used correctly which could lead to an untrusted pointer dereference.

CVEs:CVE-2018-3570

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5895

Open SourceCoalition ESS < 30%MEDIUM2018-07-06

Buffer over-read may happen in wma_process_utf_event() due to improper buffer length validation before writing into param_buf->num_wow_packet_buffer in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) ...

CVEs:CVE-2018-5895

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9416

Open SourceCoalition ESS < 30%CRITICAL2018-07-03

In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9416

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5898

Open SourceCoalition ESS < 30%CRITICAL2018-07-06

Integer overflow can occur in msm_pcm_adsp_stream_cmd_put() function if the user supplied data "param_length" goes beyond certain limit in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before securi...

CVEs:CVE-2018-5898

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9423

Open SourceCoalition ESS < 30%MEDIUM2018-07-03

In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c there is a possible out of bound read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2018-9423

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5832

Open SourceCoalition ESS < 30%CRITICAL2018-07-06

Due to a race condition in a camera driver ioctl handler in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a Use After Free condition can occur.

CVEs:CVE-2018-5832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5859

Open SourceCoalition ESS < 30%CRITICAL2018-07-03

Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a Use After Free condition can occur.

CVEs:CVE-2018-5859

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9434

Open SourceCoalition ESS < 30%HIGH2018-07-03

In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9434

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9376

Open SourceCoalition ESS < 30%HIGH2018-07-03

In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. Us...

CVEs:CVE-2018-9376

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9428

Open SourceCoalition ESS < 30%HIGH2018-07-03

In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation...

CVEs:CVE-2018-9428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9431

Open SourceCoalition ESS < 30%HIGH2018-07-03

In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9431

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9412

Open SourceCoalition ESS < 30%HIGH2018-07-03

In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9412

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9414

Open SourceCoalition ESS < 30%HIGH2018-07-03

In gattServerSendResponseNative of com_android_bluetooth_gatt.cpp, there is a possible out of bounds stack write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction ...

CVEs:CVE-2018-9414

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9417

Open SourceCoalition ESS < 30%HIGH2018-07-03

In f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9417

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9424

Open SourceCoalition ESS < 30%HIGH2018-07-03

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2018-9424

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9432

Open SourceCoalition ESS < 30%HIGH2018-07-03

In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing the user's ability to disable access to conta...

CVEs:CVE-2018-9432

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9410

Open SourceCoalition ESS < 30%MEDIUM2018-07-03

In analyzeAxes of FontUtils.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9410

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9420

Open SourceCoalition ESS < 30%MEDIUM2018-07-03

In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2018-9420

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9421

Open SourceCoalition ESS < 30%HIGH2018-07-03

In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2018-9421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-14043

Open SourceEPSS <= 49%CRITICAL2018-07-13

mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) during a copy operation, related to fs/m_fs.c and fs/...

CVEs:CVE-2018-14043

Affected products

ProductStatusVendorPackageEcosystem
mstdlib affected monetra
Upstream advisory

DEBIAN-CVE-2018-13420

GoogleEPSS <= 49%HIGH2018-07-07

DEBIAN-CVE-2018-13420

Affected products

ProductStatusVendorPackageEcosystem
google-perftools affected Debian:12 google-perftools
google-perftools affected Debian:13 google-perftools
google-perftools affected Debian:11 google-perftools
google-perftools affected Debian:14 google-perftools
Upstream advisory

CVE-2018-13850

Open SourceEPSS <= 49%CRITICAL2018-07-10

The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter.

CVEs:CVE-2018-13850

Affected products

ProductStatusVendorPackageEcosystem
firebase_push_notification_on_ios_\/_fcm_\+_advance_admin_panel affected icanstudioz
Upstream advisory

CVE-2018-13339

Open SourceEPSS <= 49%CRITICAL2018-07-05

Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.

CVEs:CVE-2018-13339

Affected products

ProductStatusVendorPackageEcosystem
angular_redactor affected angular_redactor_project
Upstream advisory

CVE-2018-13339

Open SourceEPSS <= 49%MEDIUM2018-07-05

Angular Redactor XSS Vulnerability

CVEs:CVE-2018-13339

Affected products

ProductStatusVendorPackageEcosystem
angular-redactor affected npm angular-redactor
Upstream advisory

CVE-2018-13339

Open SourceEPSS <= 49%MEDIUM2018-07-05

Angular Redactor XSS Vulnerability

CVEs:CVE-2018-13339

Affected products

ProductStatusVendorPackageEcosystem
angular-redactor affected npm angular-redactor
Upstream advisory

CVE-2018-14066

Open SourceEPSS <= 49%CRITICAL2018-07-15

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects ...

CVEs:CVE-2018-14066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15851

Open SourceEPSS <= 49%HIGH2018-07-03

Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera crash in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel

CVEs:CVE-2017-15851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14872

Open SourceEPSS <= 49%MEDIUM2018-07-06

While flashing a meta image, a buffer over-read can potentially occur when the number of images are out of the maximum range of 32 in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security pa...

CVEs:CVE-2017-14872

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-14893

Open SourceEPSS <= 49%MEDIUM2018-07-06

While flashing meta image, a buffer over-read may potentially occur when the image size is smaller than the image header size or is smaller than the image header size + total image header entry in Android releases from CAF using the linux kernel (Andro...

CVEs:CVE-2017-14893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11304

Open SourceEPSS <= 49%CRITICAL2018-07-03

Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

CVEs:CVE-2018-11304

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15824

Open SourceEPSS <= 49%MEDIUM2018-07-06

In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, the function UpdateDeviceStatus() writes a local stack buffer without initialization to flash memory using Wr...

CVEs:CVE-2017-15824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15856

Open SourceEPSS <= 49%CRITICAL2018-07-06

Due to a race condition while processing the power stats debug file to read status, a double free condition can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 201...

CVEs:CVE-2017-15856

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.