|
268551
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9028
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268552
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9027
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268553
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9026
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268554
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9025
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268555
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
|
CWE-284
Improper Access Control
|
CVE-2015-9024
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268556
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9023
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268557
|
7.0 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs.
|
CWE-362
Race Condition
|
CVE-2015-9022
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268558
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
|
CWE-284
Improper Access Control
|
CVE-2015-9021
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268559
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9020
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268560
|
6.1 |
MEDIUM
Network
|
mail_project
|
mail
|
The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences imm…
|
CWE-93
CRLF Injection
|
CVE-2015-9097
|
2024-11-21 11:39 |
2017-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|