CVE-2018-9493
- EPSS 0.73%
- Veröffentlicht 02.10.2018 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:15:35
In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex...
CVE-2018-9496
- EPSS 1.22%
- Veröffentlicht 02.10.2018 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:15:35
In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploi...
CVE-2018-9491
- EPSS 0.33%
- Veröffentlicht 02.10.2018 19:29:04
- Zuletzt bearbeitet 21.11.2024 04:15:34
In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in external apps with no additional execution privileges needed. User interaction is neede...
CVE-2018-9492
- EPSS 0.03%
- Veröffentlicht 02.10.2018 19:29:04
- Zuletzt bearbeitet 21.11.2024 04:15:34
In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation....
CVE-2018-9490
- EPSS 0.42%
- Veröffentlicht 02.10.2018 19:29:03
- Zuletzt bearbeitet 21.11.2024 04:15:34
In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation...
CVE-2018-9473
- EPSS 0.33%
- Veröffentlicht 02.10.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:15:32
In ihevcd_parse_sei_payload of ihevcd_parse_headers.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploit...
- EPSS 6.06%
- Veröffentlicht 02.10.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:15:32
In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper locking. This could lead to remote escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is n...
CVE-2018-9452
- EPSS 0.37%
- Veröffentlicht 02.10.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:15:30
In getOffsetForHorizontal of Layout.java, there is a possible application hang due to a slow width calculation. This could lead to remote denial of service if a contact with many hidden unicode characters were sent to the device and used by a local a...
CVE-2018-3573
- EPSS 0.02%
- Veröffentlicht 19.09.2018 14:29:02
- Zuletzt bearbeitet 21.11.2024 04:05:41
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while relocating kernel images with a specially crafted boot image, an out of bounds access can occur.
CVE-2018-3574
- EPSS 0.05%
- Veröffentlicht 19.09.2018 14:29:02
- Zuletzt bearbeitet 21.11.2024 04:05:41
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, userspace can request ION cache maintenance on a secure ION buffer for which the ION_FLAG_SECURE ion flag is not set and cause the kernel to a...