Advisories
GoogleExploitedCISA KEV listedCRITICAL2018-08-15
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet E...
CVEs:CVE-2018-8373
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| internet_explorer |
affected |
microsoft |
— |
— |
GoogleExploitedCISA KEV listedHIGH2018-08-15
CVEs:CVE-2018-8373
Project ZeroExploitedCISA KEV listed2018-08-15
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.
CVEs:CVE-2018-8373
Google CloudExploitedVulnCheck KEV listed2018-08-06
Date published: 2018-08-06 (High)
Google CloudExploitedVulnCheck KEV listed2018-08-06
GCP-COMPUTE-20180806 (High)
Open SourceWeaponized exploitHIGH2018-08-07
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when mounting a USB device with no additional execution privileges needed. User interaction is not needed fo...
CVEs:CVE-2018-9445
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleWeaponized exploitHIGH2018-08-07
CVEs:CVE-2018-9445
GoogleActive exploitation (sightings)HIGH2018-08-07
CVEs:CVE-2018-9464
Open SourceActive exploitation (sightings)HIGH2018-08-07
In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2018-9464
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)MEDIUM2018-08-07
CVEs:CVE-2018-9447
Open SourceActive exploitation (sightings)MEDIUM2018-08-07
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction i...
CVEs:CVE-2018-9447
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleActive exploitation (sightings)HIGH2018-08-07
CVEs:CVE-2018-9461
Open SourceActive exploitation (sightings)HIGH2018-08-07
In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVEs:CVE-2018-9461
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Google CloudCoalition ESS > 63%2018-08-14
Date published: 2018-08-14 (High)
Google CloudCoalition ESS > 63%2018-08-14
GCP-COMPUTE-20180814 (High)
Open SourceCoalition ESS < 30%CRITICAL2018-08-17
Updated chromium-browser-stable packages fix security vulnerabilities
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium-browser-stable |
affected |
Mageia:6 |
chromium-browser-stable |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9450
Open SourceCoalition ESS < 30%HIGH2018-08-07
In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2018-9450
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-08-07
In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2018-9446
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2018-08-07
CVEs:CVE-2018-9446
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9427
Open SourceCoalition ESS < 30%HIGH2018-08-07
In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation...
CVEs:CVE-2018-9427
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-08-07
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...
CVEs:CVE-2018-9436
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9436
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9459
Open SourceCoalition ESS < 30%HIGH2018-08-07
In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal error. This could lead to a remote escalation of privilege with no additional execution privileges needed...
CVEs:CVE-2018-9459
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-08-07
In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2018-9448
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9448
Open SourceCoalition ESS < 30%HIGH2018-08-07
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2018-9455
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9455
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9437
Open SourceCoalition ESS < 30%HIGH2018-08-07
In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Vers...
CVEs:CVE-2018-9437
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-23
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that u...
CVEs:CVE-2018-6558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fscrypt |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-23
Privilege Escalation in fscrypt
CVEs:CVE-2018-6558
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| google/fscrypt |
affected |
github.com |
github.com/google/fscrypt |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9458
Open SourceCoalition ESS < 30%HIGH2018-08-07
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing the user's keypresses while the ...
CVEs:CVE-2018-9458
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-08-07
In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interactio...
CVEs:CVE-2018-9444
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9444
Open SourceCoalition ESS < 30%HIGH2018-08-07
In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Pr...
CVEs:CVE-2018-9465
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9465
Open SourceCoalition ESS < 30%CRITICAL2018-08-07
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible buffer overflow in display function due to lack of buffer length validation before copying.
CVEs:CVE-2018-5908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-5908
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-5909
Open SourceCoalition ESS < 30%CRITICAL2018-08-07
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overflow occur may occur in display handlers due to lack of checking in buffer size before copying into it and will lead to memory corrupt...
CVEs:CVE-2018-5909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2018-08-07
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pro...
CVEs:CVE-2018-9454
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9454
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9438
Open SourceCoalition ESS < 30%MEDIUM2018-08-07
When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. This could lead to a local denial of service of security updates with no additional execution privileges needed. User interaction is ne...
CVEs:CVE-2018-9438
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-5910
Open SourceCoalition ESS < 30%CRITICAL2018-08-07
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a memory corruption can occur in kernel due to improper check in callers count parameter in display handlers.
CVEs:CVE-2018-5910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9451
Open SourceCoalition ESS < 30%HIGH2018-08-07
In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2018-9451
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2018-08-07
In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. P...
CVEs:CVE-2018-9453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9453
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-5904
Open SourceCoalition ESS < 30%CRITICAL2018-08-07
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while list traversal in LPM status driver for clean up, use after free vulnerability may occur.
CVEs:CVE-2018-5904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2018-08-07
In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interactio...
CVEs:CVE-2018-9457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9457
Open SourceCoalition ESS < 30%HIGH2018-08-07
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a race condition while accessing num of clients in DIAG services can lead to out of boundary access.
CVEs:CVE-2018-5905
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-5905
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9441
Open SourceCoalition ESS < 30%MEDIUM2018-08-07
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploit...
CVEs:CVE-2018-9441
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9435
Open SourceCoalition ESS < 30%MEDIUM2018-08-07
In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2018-9435
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9462
Open SourceCoalition ESS < 30%HIGH2018-08-07
In store_cmd of ftm4_pdc.c, there is a possible out of bounds write due to
an incorrect bounds check. This could lead to local escalation of privilege
with System execution privileges needed. User interaction is not needed for
exploitation.
CVEs:CVE-2018-9462
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2018-08-07
In sw49408_irq_runtime_engine_debug of touch_sw49408.c, there is a possible
out of bounds write due to an incorrect bounds check. This could lead to
local escalation of privilege with System execution privileges needed. User
interaction is ...
CVEs:CVE-2018-9463
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9463
GoogleCoalition ESS < 30%HIGH2018-08-07
CVEs:CVE-2018-9439
Open SourceCoalition ESS < 30%HIGH2018-08-07
In __unregister_prot_hook and packet_release of af_packet.c, there is a
possible use-after-free due to improper locking. This could lead to local
escalation of privilege in the kernel with System execution privileges
needed. User interactio...
CVEs:CVE-2018-9439
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2018-08-07
CVEs:CVE-2018-9449
Open SourceCoalition ESS < 30%MEDIUM2018-08-07
In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2018-9449
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%HIGH2018-08-01
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
CVEs:CVE-2018-1999040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
jenkins |
— |
— |
Open SourceEPSS <= 49%HIGH2018-08-01
Exposure of Sensitive Information in Jenkins Kubernetes Plugin
CVEs:CVE-2018-1999040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| org.csanchez.jenkins.plugins:kubernetes |
affected |
Maven |
org.csanchez.jenkins.plugins:kubernetes |
— |
GoogleEPSS <= 49%HIGH2018-08-28
CVEs:CVE-2017-15406
GoogleEPSS <= 49%CRITICAL2018-08-28
A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVEs:CVE-2017-15406
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceEPSS <= 49%CRITICAL2018-08-17
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.
CVEs:CVE-2018-15482
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2018-08-17
CVEs:CVE-2018-15482
Open SourceEPSS <= 49%CRITICAL2018-08-17
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.
CVEs:CVE-2018-14981
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2018-08-17
CVEs:CVE-2018-14981
Open SourceEPSS <= 49%CRITICAL2018-08-17
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.
CVEs:CVE-2018-14982
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2018-08-17
CVEs:CVE-2018-14982
GoogleEPSS <= 49%CRITICAL2018-08-28
Insufficient data validation in Chromecast plugin in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CVEs:CVE-2017-15430
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2018-08-28
CVEs:CVE-2017-15430
Open SourceEPSS <= 49%HIGH2018-08-07
In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is received from the FW and is used to access the buffer to copy the radio stats received for each radio from FW. If the radio_id recei...
CVEs:CVE-2018-11263
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2018-08-07
CVEs:CVE-2018-11263
GoogleEPSS <= 49%HIGH2018-08-07
CVEs:CVE-2018-11260
Open SourceEPSS <= 49%CRITICAL2018-08-07
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a fast Initial link setup (FILS) connection request, integer overflow may lead to a buffer overflow when the key length is zero.
CVEs:CVE-2018-11260
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceEPSS <= 49%MEDIUM2018-08-07
A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read access in all Android releases from CAF using the linux kernel
CVEs:CVE-2017-18281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%MEDIUM2018-08-07
CVEs:CVE-2017-18281