|
251111
|
7.8 |
HIGH
Local
|
google
|
android
|
In the video_ioctl2() function in the camera driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-16, an untrusted pointer dereference may potentially occur.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15846
|
2024-11-21 12:15 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251112
|
7.8 |
HIGH
Local
|
google
|
android
|
Due to a race condition in MDSS rotator in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-20, a double free vulnerability may potentially exist when two threads free the same per…
|
CWE-362 CWE-415
Race Condition Double Free
|
CVE-2017-15826
|
2024-11-21 12:15 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251113
|
7.8 |
HIGH
Local
|
google
|
android
|
In spectral_create_samp_msg() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-11, some values from firmware are not properly validated potentially leading to a buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15823
|
2024-11-21 12:15 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251114
|
8.1 |
HIGH
Network
|
apache debian canonical netapp redhat
|
http_server debian_linux ubuntu_linux santricity_cloud_connector storage_automation_store storagegrid clustered_data_ontap enterprise_linux
|
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could…
|
CWE-20
Improper Input Validation
|
CVE-2017-15715
|
2024-11-21 12:15 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251115
|
7.5 |
HIGH
Network
|
apache debian canonical netapp redhat
|
http_server debian_linux ubuntu_linux santricity_cloud_connector storage_automation_store storagegrid clustered_data_ontap enterprise_linux
|
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset en…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15710
|
2024-11-21 12:15 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251116
|
7.0 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, race condition in diag_dbgfs_read_dcistats(), while accessing diag_dbgfs_dci_data_index…
|
CWE-119 CWE-362
Incorrect Access of Indexable Resource ('Range Error') Race Condition
|
CVE-2017-15834
|
2024-11-21 12:15 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251117
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, untrusted pointer dereference in update_userspace_power() function in power leads to in…
|
CWE-200 CWE-476
Information Exposure NULL Pointer Dereference
|
CVE-2017-15833
|
2024-11-21 12:15 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251118
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function wma_ndp_end_indication_event_handler(), there is no input validation ch…
|
CWE-20 CWE-190
Improper Input Validation Integer Overflow or Wraparound
|
CVE-2017-15831
|
2024-11-21 12:15 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251119
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper ch_list array index initialization in function sme_set_plm_request() causes po…
|
CWE-119 CWE-129
Incorrect Access of Indexable Resource ('Range Error') Improper Validation of Array Index
|
CVE-2017-15830
|
2024-11-21 12:15 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251120
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in msm_flash_subdev_do_ioctl of drivers/media/platform/msm/camera_v2/sensor/flash/msm_f…
|
CWE-200 CWE-125
Information Exposure Out-of-bounds Read
|
CVE-2017-15814
|
2024-11-21 12:15 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|