|
251961
|
9.8 |
CRITICAL
Network
|
google
|
android
|
While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL commands there is no mutex lock of allocated memory. If one thread sends an ioctl cm…
|
CWE-416
Use After Free
|
CVE-2017-14877
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251962
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-18, if the value param_buf->num_debug_register received from the F…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14883
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251963
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter params->entries[i].vfe_intf comes from userspace without any bounds check which c…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-14876
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251964
|
7.5 |
HIGH
Network
|
google
|
android
|
In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a heap overread vulnerability exists.
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2017-14875
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251965
|
9.8 |
CRITICAL
Network
|
qualcomm
|
sd_625_firmware sd_650_firmware sd_652_firmware sd_835_firmware
|
In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client structure can result in a Use After Free condition.
|
CWE-416
Use After Free
|
CVE-2017-14915
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251966
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware sd_625_firmware sd_650_firmware sd_652_firmware sd_835_firmware sd_845_firmware
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, SD 625, SD 650/52, SD 835, SD 845, DDR address input validation is being improperly truncated.
|
CWE-20
Improper Input Validation
|
CVE-2017-14913
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251967
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_400_firmware sd_410_firmware sd_412_firmware sd_4…
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile [VERSION]: MDM9206, MDM9607, MDM9650, MSM8909W, SD 200, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/S…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14912
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251968
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware apq8096au_firmware msm8996au_firmware mdm9650_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_430_firmware sd_625_firmware s…
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 625, SD 650/52, SD 8…
|
CWE-287
Improper Authentication
|
CVE-2017-14911
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251969
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.
|
NVD-CWE-noinfo
|
CVE-2017-14906
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251970
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to the lack of a range check on the array index into the WMI descriptor pool, arbit…
|
CWE-129
Improper Validation of Array Index
|
CVE-2017-14889
|
2024-11-21 12:13 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|