CVE-2018-5857
- EPSS 0.02%
- Veröffentlicht 15.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:33
In the WCD CPE codec, a Use After Free condition can occur in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:32
Due to a race condition in the QTEECOM driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, when more than one HLOS client loads the same TA, a Use After Free condition can occur.
CVE-2018-5851
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:32
Buffer over flow can occur while processing a HTT_T2H_MSG_TYPE_TX_COMPL_IND message with an out-of-range num_msdus value in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
CVE-2017-15842
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:19
Buffer might get used after it gets freed due to unlocking the mutex before freeing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- EPSS 0.01%
- Veröffentlicht 12.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:19
Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
CVE-2017-15854
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:20
The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma_radio_chan_stats_event_handler() for the derived length len leading to a subsequent buffer overflow in all Android releases from ...
CVE-2017-15857
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:20
In the camera driver, an out-of-bounds access can occur due to an error in copying region params from user space in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
CVE-2017-18070
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:17
In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in a...
CVE-2018-3571
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:41
In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations
CVE-2018-3572
- EPSS 0.02%
- Veröffentlicht 12.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:41
While processing a DSP buffer in an audio driver's event handler, an index of a buffer is not checked before accessing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.