Google Security Advisories · September 2018 — Google Security Advisories
224 advisories 113 CVEs 2 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2018-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2018-6055

GoogleExploitedVulnCheck KEV listedCRITICAL2018-09-25

Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted HTML page.

CVEs:CVE-2018-6055

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DSA-4289-1

Open SourceWeaponized exploit2018-09-07

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

CVE-2018-16083

GoogleWeaponized exploitHIGH2018-09-05

An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVEs:CVE-2018-16083

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16071

GoogleWeaponized exploitCRITICAL2018-09-05

A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

CVEs:CVE-2018-16071

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16068

GoogleWeaponized exploitCRITICAL2018-09-05

Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2018-16068

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-9488

Open SourceWeaponized exploitHIGH2018-09-05

In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed for exploitation. Product: Androi...

CVEs:CVE-2018-9488

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9478

Open SourceActive exploitation (sightings)CRITICAL2018-09-05

In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction...

CVEs:CVE-2018-9478

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9484

Open SourceActive exploitation (sightings)HIGH2018-09-05

In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2018-9484

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9472

Open SourceActive exploitation (sightings)HIGH2018-09-05

In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for ex...

CVEs:CVE-2018-9472

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9470

Open SourceActive exploitation (sightings)HIGH2018-09-05

In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction i...

CVEs:CVE-2018-9470

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9468

Open SourceActive exploitation (sightings)HIGH2018-09-05

In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2018-9468

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9471

Open SourceActive exploitation (sightings)CRITICAL2018-09-05

In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2018-9471

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9475

Open SourceActive exploitation (sightings)HIGH2018-09-05

In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation of privilege via Bluetooth, if the recipient has enabled SIP calls with no additional exe...

CVEs:CVE-2018-9475

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9483

Open SourceActive exploitation (sightings)HIGH2018-09-05

In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not nee...

CVEs:CVE-2018-9483

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9485

Open SourceActive exploitation (sightings)MEDIUM2018-09-05

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2018-9485

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9487

Open SourceActive exploitation (sightings)HIGH2018-09-05

In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn due to a bad uid check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9487

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9486

Open SourceActive exploitation (sightings)MEDIUM2018-09-05

In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2018-9486

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9474

Open SourceActive exploitation (sightings)HIGH2018-09-05

In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2018-9474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9477

Open SourceActive exploitation (sightings)HIGH2018-09-05

In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ne...

CVEs:CVE-2018-9477

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9469

Open SourceActive exploitation (sightings)HIGH2018-09-05

In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local escalation of privilege in a privileged app with no additional execution privileges needed. Us...

CVEs:CVE-2018-9469

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-6119

GoogleCoalition ESS < 30%MEDIUM2018-09-25

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-6119

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-9517

Open SourceCoalition ESS < 30%HIGH2018-09-05

In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: And...

CVEs:CVE-2018-9517

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9479

Open SourceCoalition ESS < 30%CRITICAL2018-09-05

In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction...

CVEs:CVE-2018-9479

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9467

Open SourceCoalition ESS < 30%CRITICAL2018-09-05

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9467

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9466

Open SourceCoalition ESS < 30%HIGH2018-09-05

In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for explo...

CVEs:CVE-2018-9466

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9456

Open SourceCoalition ESS < 30%HIGH2018-09-05

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2018-9456

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3574

Open SourceCoalition ESS < 30%MEDIUM2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, userspace can request ION cache maintenance on a secure ION buffer for which the ION_FLAG_SECURE ion flag is not set and cause the kernel to att...

CVEs:CVE-2018-3574

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9518

Open SourceCoalition ESS < 30%HIGH2018-09-05

In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2018-9518

Affected products

ProductStatusVendorPackageEcosystem
android affected google
ubuntu_linux affected canonical
Upstream advisory

CVE-2018-9440

Open SourceCoalition ESS < 30%HIGH2018-09-05

In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2018-9440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-3573

Open SourceCoalition ESS < 30%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while relocating kernel images with a specially crafted boot image, an out of bounds access can occur.

CVEs:CVE-2018-3573

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9480

Open SourceCoalition ESS < 30%MEDIUM2018-09-05

In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interacti...

CVEs:CVE-2018-9480

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9481

Open SourceCoalition ESS < 30%HIGH2018-09-05

In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2018-9481

Affected products

ProductStatusVendorPackageEcosystem
android affected google
traffic_server affected apache
Upstream advisory

CVE-2018-9519

Open SourceCoalition ESS < 30%HIGH2018-09-05

In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation. Product: Android. Ver...

CVEs:CVE-2018-9519

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-9482

Open SourceCoalition ESS < 30%HIGH2018-09-05

In intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2018-9482

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-16065

GoogleEPSS <= 49%CRITICAL2018-09-05

A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVEs:CVE-2018-16065

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-17075

GoogleEPSS <= 49%HIGH2018-09-16

The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder....

CVEs:CVE-2018-17075

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
net affected golang
Upstream advisory

CVE-2018-17075

Open SourceEPSS <= 49%HIGH2018-09-16

golang.org/x/net/html NULL Pointer Dereference vulnerability

CVEs:CVE-2018-17075

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2018-17075

Open SourceEPSS <= 49%HIGH2018-09-16

golang.org/x/net/html NULL Pointer Dereference vulnerability

CVEs:CVE-2018-17075

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2018-17143

GoogleEPSS <= 49%HIGH2018-09-17

The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.

CVEs:CVE-2018-17143

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
net affected golang
Upstream advisory

CVE-2018-17143

Open SourceEPSS <= 49%HIGH2018-09-17

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

CVEs:CVE-2018-17143

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2018-17142

Open SourceEPSS <= 49%HIGH2018-09-17

golang.org/x/net/html NULL Pointer Dereference vulnerability

CVEs:CVE-2018-17142

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2018-17142

Open SourceEPSS <= 49%HIGH2018-09-17

golang.org/x/net/html NULL Pointer Dereference vulnerability

CVEs:CVE-2018-17142

Affected products

ProductStatusVendorPackageEcosystem
x/net affected golang.org golang.org/x/net
Upstream advisory

CVE-2018-17142

GoogleEPSS <= 49%HIGH2018-09-17

The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.

CVEs:CVE-2018-17142

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
net affected golang
Upstream advisory

DSA-4297-1

Open SourceEPSS <= 49%2018-09-19

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:9 chromium-browser
Upstream advisory

CVE-2018-16078

GoogleEPSS <= 49%HIGH2018-09-05

Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2018-16078

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

DEBIAN-CVE-2016-7075

Open SourceEPSS <= 49%CRITICAL2018-09-10

DEBIAN-CVE-2016-7075

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2016-7075

Open SourceEPSS <= 49%CRITICAL2018-09-10

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 c...

CVEs:CVE-2016-7075

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected kubernetes
openshift affected redhat
Upstream advisory

CVE-2018-16082

GoogleEPSS <= 49%MEDIUM2018-09-05

An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVEs:CVE-2018-16082

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16085

GoogleEPSS <= 49%CRITICAL2018-09-05

A use after free in ResourceCoordinator in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-16085

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16076

GoogleEPSS <= 49%HIGH2018-09-05

Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

CVEs:CVE-2018-16076

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16066

GoogleEPSS <= 49%CRITICAL2018-09-05

A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-16066

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16067

GoogleEPSS <= 49%CRITICAL2018-09-05

A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-16067

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16080

GoogleEPSS <= 49%MEDIUM2018-09-05

A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-16080

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16084

GoogleEPSS <= 49%MEDIUM2018-09-05

The default selected dialog button in CustomHandlers in Google Chrome prior to 69.0.3497.81 allowed a remote attacker who convinced the user to perform certain operations to open external programs via a crafted HTML page.

CVEs:CVE-2018-16084

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16079

GoogleEPSS <= 49%MEDIUM2018-09-05

A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2018-16079

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16081

GoogleEPSS <= 49%HIGH2018-09-05

Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system without file access permission...

CVEs:CVE-2018-16081

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2018-16069

GoogleEPSS <= 49%MEDIUM2018-09-05

Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVEs:CVE-2018-16069

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16070

GoogleEPSS <= 49%CRITICAL2018-09-05

Integer overflows in Skia in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2018-16070

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16075

GoogleEPSS <= 49%CRITICAL2018-09-05

Insufficient file type enforcement in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain local file data via a crafted HTML page.

CVEs:CVE-2018-16075

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16073

GoogleEPSS <= 49%CRITICAL2018-09-05

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2018-16073

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16074

GoogleEPSS <= 49%CRITICAL2018-09-05

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2018-16074

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16072

GoogleEPSS <= 49%MEDIUM2018-09-05

A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2018-16072

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2018-16077

GoogleEPSS <= 49%MEDIUM2018-09-05

Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2018-16077

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-c2vr-2c89-ph88

Open SourceEPSS <= 49%HIGH2018-09-18

Downloads Resources over HTTP in node-bsdiff-android

Affected products

ProductStatusVendorPackageEcosystem
node-bsdiff-android affected npm node-bsdiff-android
Upstream advisory

GHSA-c2vr-2c89-ph88

Open SourceEPSS <= 49%HIGH2018-09-18

Downloads Resources over HTTP in node-bsdiff-android

Affected products

ProductStatusVendorPackageEcosystem
node-bsdiff-android affected npm node-bsdiff-android
Upstream advisory

CVE-2018-11891

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on the length of array while accessing can lead to an out of bound read in WLAN HOST function.

CVEs:CVE-2018-11891

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-16359

Open SourceEPSS <= 49%HIGH2018-09-02

Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.

CVEs:CVE-2018-16359

Affected products

ProductStatusVendorPackageEcosystem
gvisor affected google
Upstream advisory

CVE-2018-11293

Open SourceEPSS <= 49%MEDIUM2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, in wma_ndp_confirm_event_handler and wma_ndp_indication_event_handler, ndp_cfg len and num_ndp_app_info is from fw. If they are not checked, it ...

CVEs:CVE-2018-11293

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11904

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, asynchronous callbacks received a pointer to a callers local variable. Should the caller return early (e.g., timeout), the callback will derefer...

CVEs:CVE-2018-11904

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11294

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, WLAN handler indication from the firmware gets the information for 4 access categories. While processing this information only the first 3 AC in...

CVEs:CVE-2018-11294

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11894

Open SourceEPSS <= 49%CRITICAL2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing preferred network offload scan results integer overflow may lead to buffer overflow when large frame length is received from FW.

CVEs:CVE-2018-11894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11868

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from firmware can lead to buffer overflow in nan response event handler.

CVEs:CVE-2018-11868

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11869

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from firmware can lead to buffer overflow in WMA handler.

CVEs:CVE-2018-11869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11878

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, possibility of invalid memory access while processing driver command in WLAN function.

CVEs:CVE-2018-11878

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11826

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on integer overflow while calculating memory can lead to Buffer overflow in WLAN ext scan handler.

CVEs:CVE-2018-11826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11299

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when WLAN FW has not filled the vdev id correctly in stats events then WLAN host driver tries to access interface array without proper bound che...

CVEs:CVE-2018-11299

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11889

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when requesting rssi timeout, access invalid memory may occur since local variable 'context' stack data of wlan function is free.

CVEs:CVE-2018-11889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11895

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check Validation in WLAN function can lead to driver writes the default rsn capabilities to the memory not allocated to the frame.

CVEs:CVE-2018-11895

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11897

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing diag event after associating to a network out of bounds read occurs if ssid of the network joined is greater than max limit.

CVEs:CVE-2018-11897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11902

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from firmware can lead to OOB access in WLAN HOST.

CVEs:CVE-2018-11902

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11851

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on input received to calculate the buffer length can lead to out of bound write to kernel stack.

CVEs:CVE-2018-11851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11860

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a potential buffer over flow could occur while processing the ndp event due to lack of check on the message length.

CVEs:CVE-2018-11860

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15825

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a gpt update, an out of bounds memory access may potentially occur.

CVEs:CVE-2017-15825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11265

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, possible buffer overflow while incrementing the log_buf of type uint64_t in memcpy function, since the log_buf pointer can access the memory bey...

CVEs:CVE-2018-11265

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11298

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing SET_PASSPOINT_LIST vendor command HDD does not make sure that the realm string that gets passed by upper-layer is NULL terminat...

CVEs:CVE-2018-11298

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11262

Open SourceEPSS <= 49%HIGH2018-09-04

In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out total number of partition via a non zero check, there could be possibility where the 'TotalPart' could cross 'Gpt...

CVEs:CVE-2018-11262

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11886

Open SourceEPSS <= 49%CRITICAL2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check while calculating the MPDU data length will cause an integer overflow and then to buffer overflow in WLAN function.

CVEs:CVE-2018-11886

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11297

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a buffer over-read can occur In the WMA NDP event handler functions due to lack of validation of input value event_info which is received from FW.

CVEs:CVE-2018-11297

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11836

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check can lead to out-of-bounds access in WLAN function.

CVEs:CVE-2018-11836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11842

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, during wlan association, driver allocates memory. In case the mem allocation fails driver does a mem free though the memory was not allocated.

CVEs:CVE-2018-11842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11898

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing start bss request from upper layer, out of bounds read occurs if ssid length is greater than maximum.

CVEs:CVE-2018-11898

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11280

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing user-space there is no size validation of the NAT entry input. If the user input size of the NAT entry is greater than the max ...

CVEs:CVE-2018-11280

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11832

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of input size validation before copying to buffer in PMIC function can lead to heap overflow.

CVEs:CVE-2018-11832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11261

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible Use-after-free issue in Media Codec process. Any application using codec service will be affected.

CVEs:CVE-2018-11261

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15818

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while loading a user application in qseecom, an integer overflow could potentially occur if the application partition size is rounded up to page...

CVEs:CVE-2017-15818

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11827

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper validation of array index in WMA roam synchronization handler can lead to OOB write.

CVEs:CVE-2018-11827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11840

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the WLAN driver command ioctl a temporary buffer used to construct the reply message may be freed twice.

CVEs:CVE-2018-11840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11270

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated with devm_kzalloc is automatically released by the kernel if the probe function fails with an error code. This may result in da...

CVEs:CVE-2018-11270

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11295

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, WMA handler carries a fixed event data from the firmware to the host . If the length and anqp length from this event data exceeds the max length...

CVEs:CVE-2018-11295

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11296

Open SourceEPSS <= 49%HIGH2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a message from firmware in WLAN handler, a buffer overwrite can occur.

CVEs:CVE-2018-11296

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11274

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overflow may occur when payload size is extremely large.

CVEs:CVE-2018-11274

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11275

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashing image using FastbootLib if size is not divisible by block size, information leak occurs.

CVEs:CVE-2018-11275

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11273

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, 'voice_svc_dev' is allocated as a device-managed resource. If error 'cdev_alloc_err' occurs, 'device_destroy' will free all associated resources...

CVEs:CVE-2018-11273

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11281

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while calling IPA_IOC_MDFY_RT_RULE IPA IOCTL, header entry is not checked before use. If IPA_IOC_MDFY_RT_RULE IOCTL called for header entries fo...

CVEs:CVE-2018-11281

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11276

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, double free of memory allocation is possible in Kernel when it explicitly tries to free that memory on driver probe failure, since memory alloca...

CVEs:CVE-2018-11276

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11301

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on buffer length while processing debug log event from firmware can lead to an integer overflow.

CVEs:CVE-2018-11301

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11893

Open SourceEPSS <= 49%CRITICAL2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing vendor scan request, when input argument - length of request IEs is greater than maximum can lead to a buffer overflow.

CVEs:CVE-2018-11893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15828

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing the keystore in LK, an integer overflow vulnerability exists which may potentially lead to a buffer overflow.

CVEs:CVE-2017-15828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11300

Open SourceEPSS <= 49%CRITICAL2018-09-05

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, callback executed from the other thread has freed memory which is also used in wlan function and may result in to a "Use after free" scenario.

CVEs:CVE-2018-11300

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11302

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check of input received from userspace before copying into buffer can lead to potential array overflow in WLAN.

CVEs:CVE-2018-11302

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11883

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, in policy mgr unit test if mode parameter in wlan function is given an out of bound value it can cause an out of bound access while accessing th...

CVEs:CVE-2018-11883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11903

Open SourceEPSS <= 49%HIGH2018-09-19

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from caller function used as an array index for WMA interfaces can lead to OOB write in WLAN ...

CVEs:CVE-2018-11903

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11843

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack fo check on return value in WMA response handler can lead to potential use after free.

CVEs:CVE-2018-11843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11852

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper check In the WMA API for the inputs received from the firmware and then fills the same to the host structure will lead to OOB write.

CVEs:CVE-2018-11852

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11863

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check of input received from firmware to calculate the length of WMA roam synch buffer can lead to buffer overwrite during memcpy.

CVEs:CVE-2018-11863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11278

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Venus HW searches for start code when decoding input bit stream buffers. If start code is not found in entire buffer, there is over-fetch beyond...

CVEs:CVE-2018-11278

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11286

Open SourceEPSS <= 49%CRITICAL2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing global variable "debug_client" in multi-thread manner, Use after free issue occurs

CVEs:CVE-2018-11286

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2017-15844

Open SourceEPSS <= 49%MEDIUM2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the function for writing device values into flash, uninitialized memory can be written to flash.

CVEs:CVE-2017-15844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2018-11818

Open SourceEPSS <= 49%HIGH2018-09-18

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, LUT configuration is passed down to driver from userspace via ioctl. Simultaneous update from userspace while kernel drivers are updating LUT re...

CVEs:CVE-2018-11818

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.