CVE-2018-11840
- EPSS 0.03%
- Veröffentlicht 18.09.2018 18:29:06
- Zuletzt bearbeitet 21.11.2024 03:44:06
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the WLAN driver command ioctl a temporary buffer used to construct the reply message may be freed twice.
CVE-2018-11842
- EPSS 0.06%
- Veröffentlicht 18.09.2018 18:29:06
- Zuletzt bearbeitet 21.11.2024 03:44:06
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, during wlan association, driver allocates memory. In case the mem allocation fails driver does a mem free though the memory was not allocated.
CVE-2018-11843
- EPSS 0.02%
- Veröffentlicht 18.09.2018 18:29:06
- Zuletzt bearbeitet 21.11.2024 03:44:07
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack fo check on return value in WMA response handler can lead to potential use after free.
CVE-2018-11851
- EPSS 0.03%
- Veröffentlicht 18.09.2018 18:29:06
- Zuletzt bearbeitet 21.11.2024 03:44:07
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on input received to calculate the buffer length can lead to out of bound write to kernel stack.
CVE-2018-11302
- EPSS 0.02%
- Veröffentlicht 18.09.2018 18:29:05
- Zuletzt bearbeitet 21.11.2024 03:43:05
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check of input received from userspace before copying into buffer can lead to potential array overflow in WLAN.
- EPSS 0.02%
- Veröffentlicht 18.09.2018 18:29:05
- Zuletzt bearbeitet 21.11.2024 03:44:04
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, LUT configuration is passed down to driver from userspace via ioctl. Simultaneous update from userspace while kernel drivers are updating LUT ...
CVE-2018-11826
- EPSS 0.03%
- Veröffentlicht 18.09.2018 18:29:05
- Zuletzt bearbeitet 21.11.2024 03:44:05
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on integer overflow while calculating memory can lead to Buffer overflow in WLAN ext scan handler.
CVE-2018-11827
- EPSS 0.03%
- Veröffentlicht 18.09.2018 18:29:05
- Zuletzt bearbeitet 21.11.2024 03:44:05
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper validation of array index in WMA roam synchronization handler can lead to OOB write.
CVE-2018-11832
- EPSS 0.02%
- Veröffentlicht 18.09.2018 18:29:05
- Zuletzt bearbeitet 21.11.2024 03:44:06
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of input size validation before copying to buffer in PMIC function can lead to heap overflow.
CVE-2018-11297
- EPSS 0.02%
- Veröffentlicht 18.09.2018 18:29:04
- Zuletzt bearbeitet 21.11.2024 03:43:05
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a buffer over-read can occur In the WMA NDP event handler functions due to lack of validation of input value event_info which is received from...