CVE-2017-6284
- EPSS 0.01%
- Veröffentlicht 06.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:29:27
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive ...
CVE-2017-6295
- EPSS 0.02%
- Veröffentlicht 06.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:29:29
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is...
- EPSS 0.01%
- Veröffentlicht 06.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:29:29
NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.
CVE-2017-14884
- EPSS 0.02%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:13:41
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the function WLANQCMBR_McProcessMsg, a buffer overflow may potentially occur in WLANFTM_McProcessMsg.
CVE-2017-15817
- EPSS 0.15%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:17
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.
CVE-2017-15820
- EPSS 0.02%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:17
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a KGSL IOCTL handler, a Use After Free Condition can potentially occur.
- EPSS 0.01%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a GPU Driver which can potentially lead to a Use After Free condition.
CVE-2017-15860
- EPSS 0.05%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:21
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing an encrypted authentication management frame, a stack buffer overflow may potentially occur.
CVE-2017-15861
- EPSS 0.01%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:21
In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function wma_roam_synch_event_handler, vdev_id is received from firmware and used to access an array without validation.
CVE-2017-15862
- EPSS 0.02%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:21
In all Qualcomm products with Android releases from CAF using the Linux kernel, in wma_unified_link_radio_stats_event_handler(), the number of radio channels coming from firmware is not properly validated, potentially leading to an integer overflow v...