CVE-2017-0805
- EPSS 0.04%
- Veröffentlicht 24.08.2017 00:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.
- EPSS 0.12%
- Veröffentlicht 18.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function __mdss_fb_copy_destscaler_data(), variable ds_data[i].scale may still point to a user-provided address (which could point to arbitrary kernel address), so on ...
CVE-2017-9678
- EPSS 0.04%
- Veröffentlicht 18.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a video driver, memory corruption can potentially occur due to lack of bounds checking in a memcpy().
CVE-2017-9679
- EPSS 0.11%
- Veröffentlicht 18.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory contents can leak to system logs.
CVE-2017-9680
- EPSS 0.11%
- Veröffentlicht 18.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a driver may use an uninitialized structure to log an error message.
CVE-2017-9682
- EPSS 0.06%
- Veröffentlicht 18.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.
CVE-2017-9684
- EPSS 0.03%
- Veröffentlicht 18.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a USB driver can lead to a Use After Free condition.
CVE-2017-9685
- EPSS 0.11%
- Veröffentlicht 18.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a WLAN driver can lead to a Use After Free condition.
CVE-2016-10389
- EPSS 0.04%
- Veröffentlicht 18.08.2017 18:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partitio...
- EPSS 0.29%
- Veröffentlicht 18.08.2017 18:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive amount of memory may be consumed.