Google

Android

7931 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 23.02.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:18:36

In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an integer overflow vulnerability in a buffer size calcu...

  • EPSS 0.02%
  • Veröffentlicht 23.02.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:18:36

In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to int...

  • EPSS 0.02%
  • Veröffentlicht 23.02.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:18:37

In all Qualcomm products with Android releases from CAF using the Linux kernel, the IL client may free a buffer OMX Video Encoder Component and then subsequently access the already freed buffer.

  • EPSS 0.26%
  • Veröffentlicht 19.02.2018 19:29:00
  • Zuletzt bearbeitet 03.12.2025 22:15:49

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may exp...

  • EPSS 38.43%
  • Veröffentlicht 19.02.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:31:45

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

  • EPSS 0.01%
  • Veröffentlicht 15.02.2018 02:29:00
  • Zuletzt bearbeitet 21.11.2024 03:11:16

In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Andr...

  • EPSS 0.02%
  • Veröffentlicht 12.02.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:11:13

A elevation of privilege vulnerability in the Upstream kernel audio driver. Product: Android. Versions: Android kernel. ID: A-64315347.

  • EPSS 0.11%
  • Veröffentlicht 12.02.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:11:13

A information disclosure vulnerability in the Upstream kernel network driver. Product: Android. Versions: Android kernel. ID: A-36279469.

  • EPSS 0.02%
  • Veröffentlicht 12.02.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:11:13

In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation. Product: A...

  • EPSS 0.46%
  • Veröffentlicht 12.02.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:11:11

In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character. This could lead to remote code execution with no additional execution privileges needed. User interaction is need...