Google Security Advisories · August 2018 — Google Security Advisories
90 advisories 47 CVEs 5 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 5 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-8373

GoogleExploitedCISA KEV listedCRITICAL2018-08-15

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet E...

CVEs:CVE-2018-8373

Affected products

ProductStatusVendorPackageEcosystem
internet_explorer affected microsoft
Upstream advisory

CVE-2018-8373

Project ZeroExploitedCISA KEV listed2018-08-15

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.

CVEs:CVE-2018-8373

Upstream advisory

CVE-2018-9445

Open SourceWeaponized exploitHIGH2018-08-07

In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when mounting a USB device with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2018-9445

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9464

Open SourceActive exploitation (sightings)HIGH2018-08-07

In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9464

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9447

Open SourceActive exploitation (sightings)MEDIUM2018-08-07

In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction i...

CVEs:CVE-2018-9447

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9461

Open SourceActive exploitation (sightings)HIGH2018-08-07

In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...

CVEs:CVE-2018-9461

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2018-0343

Open SourceCoalition ESS < 30%CRITICAL2018-08-17

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:6 chromium-browser-stable
Upstream advisory

CVE-2018-9450

Open SourceCoalition ESS < 30%HIGH2018-08-07

In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2018-9450

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9446

Open SourceCoalition ESS < 30%HIGH2018-08-07

In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2018-9446

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9427

Open SourceCoalition ESS < 30%HIGH2018-08-07

In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation...

CVEs:CVE-2018-9427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9436

Open SourceCoalition ESS < 30%HIGH2018-08-07

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...

CVEs:CVE-2018-9436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9459

Open SourceCoalition ESS < 30%HIGH2018-08-07

In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal error. This could lead to a remote escalation of privilege with no additional execution privileges needed...

CVEs:CVE-2018-9459

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9448

Open SourceCoalition ESS < 30%HIGH2018-08-07

In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2018-9448

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9455

Open SourceCoalition ESS < 30%HIGH2018-08-07

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2018-9455

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9437

Open SourceCoalition ESS < 30%HIGH2018-08-07

In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Vers...

CVEs:CVE-2018-9437

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6558

GoogleCoalition ESS < 30%MEDIUM2018-08-23

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that u...

CVEs:CVE-2018-6558

Affected products

ProductStatusVendorPackageEcosystem
fscrypt affected google
Upstream advisory

CVE-2018-6558

GoogleCoalition ESS < 30%MEDIUM2018-08-23

Privilege Escalation in fscrypt

CVEs:CVE-2018-6558

Affected products

ProductStatusVendorPackageEcosystem
google/fscrypt affected github.com github.com/google/fscrypt
Upstream advisory

CVE-2018-9458

Open SourceCoalition ESS < 30%HIGH2018-08-07

In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing the user's keypresses while the ...

CVEs:CVE-2018-9458

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9444

Open SourceCoalition ESS < 30%HIGH2018-08-07

In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interactio...

CVEs:CVE-2018-9444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9465

Open SourceCoalition ESS < 30%HIGH2018-08-07

In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...

CVEs:CVE-2018-9465

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5908

Open SourceCoalition ESS < 30%CRITICAL2018-08-07

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible buffer overflow in display function due to lack of buffer length validation before copying.

CVEs:CVE-2018-5908

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5909

Open SourceCoalition ESS < 30%CRITICAL2018-08-07

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overflow occur may occur in display handlers due to lack of checking in buffer size before copying into it and will lead to memory corrupt...

CVEs:CVE-2018-5909

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9454

Open SourceCoalition ESS < 30%MEDIUM2018-08-07

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pro...

CVEs:CVE-2018-9454

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9438

Open SourceCoalition ESS < 30%MEDIUM2018-08-07

When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. This could lead to a local denial of service of security updates with no additional execution privileges needed. User interaction is ne...

CVEs:CVE-2018-9438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5910

Open SourceCoalition ESS < 30%CRITICAL2018-08-07

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a memory corruption can occur in kernel due to improper check in callers count parameter in display handlers.

CVEs:CVE-2018-5910

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9451

Open SourceCoalition ESS < 30%HIGH2018-08-07

In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2018-9451

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9453

Open SourceCoalition ESS < 30%MEDIUM2018-08-07

In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. P...

CVEs:CVE-2018-9453

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5904

Open SourceCoalition ESS < 30%CRITICAL2018-08-07

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while list traversal in LPM status driver for clean up, use after free vulnerability may occur.

CVEs:CVE-2018-5904

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9457

Open SourceCoalition ESS < 30%HIGH2018-08-07

In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interactio...

CVEs:CVE-2018-9457

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-5905

Open SourceCoalition ESS < 30%HIGH2018-08-07

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a race condition while accessing num of clients in DIAG services can lead to out of boundary access.

CVEs:CVE-2018-5905

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9441

Open SourceCoalition ESS < 30%MEDIUM2018-08-07

In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploit...

CVEs:CVE-2018-9441

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9435

Open SourceCoalition ESS < 30%MEDIUM2018-08-07

In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2018-9435

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9462

Open SourceCoalition ESS < 30%HIGH2018-08-07

In store_cmd of ftm4_pdc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9462

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9463

Open SourceCoalition ESS < 30%CRITICAL2018-08-07

In sw49408_irq_runtime_engine_debug of touch_sw49408.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is ...

CVEs:CVE-2018-9463

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9439

Open SourceCoalition ESS < 30%HIGH2018-08-07

In __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interactio...

CVEs:CVE-2018-9439

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9449

Open SourceCoalition ESS < 30%MEDIUM2018-08-07

In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2018-9449

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-1999040

Open SourceEPSS <= 49%HIGH2018-08-01

An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

CVEs:CVE-2018-1999040

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected jenkins
Upstream advisory

CVE-2018-1999040

Open SourceEPSS <= 49%HIGH2018-08-01

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

CVEs:CVE-2018-1999040

Affected products

ProductStatusVendorPackageEcosystem
org.csanchez.jenkins.plugins:kubernetes affected Maven org.csanchez.jenkins.plugins:kubernetes
Upstream advisory

CVE-2017-15406

GoogleEPSS <= 49%CRITICAL2018-08-28

A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2017-15406

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-15482

Open SourceEPSS <= 49%CRITICAL2018-08-17

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.

CVEs:CVE-2018-15482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-14981

Open SourceEPSS <= 49%CRITICAL2018-08-17

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.

CVEs:CVE-2018-14981

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-14982

Open SourceEPSS <= 49%CRITICAL2018-08-17

Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.

CVEs:CVE-2018-14982

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15430

GoogleEPSS <= 49%CRITICAL2018-08-28

Insufficient data validation in Chromecast plugin in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

CVEs:CVE-2017-15430

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-11263

Open SourceEPSS <= 49%HIGH2018-08-07

In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is received from the FW and is used to access the buffer to copy the radio stats received for each radio from FW. If the radio_id recei...

CVEs:CVE-2018-11263

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11260

Open SourceEPSS <= 49%CRITICAL2018-08-07

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a fast Initial link setup (FILS) connection request, integer overflow may lead to a buffer overflow when the key length is zero.

CVEs:CVE-2018-11260

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-18281

Open SourceEPSS <= 49%MEDIUM2018-08-07

A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read access in all Android releases from CAF using the linux kernel

CVEs:CVE-2017-18281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.