|
254861
|
7.5 |
HIGH
Network
|
google
|
android
|
A information disclosure vulnerability in the Android media framework (libstagefright_soft_avcenc). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-69065651.
|
CWE-200
Information Exposure
|
CVE-2017-13241
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254862
|
7.5 |
HIGH
Network
|
google
|
android
|
A information disclosure vulnerability in the Android framework (crypto framework). Product: Android. Versions: 8.0, 8.1. ID: A-68694819.
|
CWE-200
Information Exposure
|
CVE-2017-13240
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254863
|
7.5 |
HIGH
Network
|
google
|
android
|
A information disclosure vulnerability in the Android framework (ui framework). Product: Android. Versions: 8.0. ID: A-66244132.
|
CWE-200
Information Exposure
|
CVE-2017-13239
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254864
|
4.2 |
MEDIUM
Physics
|
google
|
android
|
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additi…
|
CWE-200
Information Exposure
|
CVE-2017-13238
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254865
|
7.8 |
HIGH
Local
|
google
|
android
|
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User intera…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-13236
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254866
|
6.5 |
MEDIUM
Network
|
google
|
android
|
A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68342866.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-13235
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254867
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-13234
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254868
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-13233
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254869
|
7.5 |
HIGH
Network
|
google
|
android
|
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execu…
|
CWE-200 CWE-787
Information Exposure Out-of-bounds Write
|
CVE-2017-13232
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254870
|
7.8 |
HIGH
Local
|
google
|
android
|
In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is …
|
CWE-787
Out-of-bounds Write
|
CVE-2017-13231
|
2024-11-21 12:11 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|