|
277791
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths was missing in Keymaster.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9974
|
2024-11-21 11:22 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277792
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missing in a PlayReady DRM routine.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9973
|
2024-11-21 11:22 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277793
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.
|
CWE-476
NULL Pointer Dereference
|
CVE-2014-9972
|
2024-11-21 11:22 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277794
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.
|
CWE-20
Improper Input Validation
|
CVE-2014-9971
|
2024-11-21 11:22 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277795
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the GPS client may use an insecure cryptographic algorithm.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2014-9969
|
2024-11-21 11:22 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277796
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the UIMDIAG interface.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9968
|
2024-11-21 11:22 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277797
|
6.5 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator sterling_file_gateway
|
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
|
CWE-611
XXE
|
CVE-2015-0194
|
2024-11-21 11:22 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277798
|
7.2 |
HIGH
Network
|
apache
|
roller
|
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka…
|
CWE-94
Code Injection
|
CVE-2015-0249
|
2024-11-21 11:22 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277799
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
|
CWE-476
NULL Pointer Dereference
|
CVE-2014-9967
|
2024-11-21 11:22 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277800
|
7.0 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.
|
CWE-362
Race Condition
|
CVE-2014-9966
|
2024-11-21 11:22 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|