|
253401
|
7.3 |
HIGH
Network
|
google
|
android
|
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the processing of an SWBA event, …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14890
|
2024-11-21 12:13 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253402
|
7.8 |
HIGH
Local
|
google
|
android
|
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while IPA WAN-driver is processing m…
|
CWE-362
Race Condition
|
CVE-2017-14880
|
2024-11-21 12:13 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253403
|
7.8 |
HIGH
Local
|
google
|
android
|
In the function msm_pcm_hw_params() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-19, the return value of q6asm_open_shared_io() is not checked properly potentially leading t…
|
CWE-20
Improper Input Validation
|
CVE-2017-14892
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253404
|
5.3 |
MEDIUM
Network
|
google
|
android
|
In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the stack can get leaked due to an uninitialized variable.
|
CWE-200
Information Exposure
|
CVE-2017-14891
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253405
|
9.8 |
CRITICAL
Network
|
google
|
android
|
While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-13, a use-after-free condition may potentially occur.
|
CWE-416
Use After Free
|
CVE-2017-14881
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253406
|
9.8 |
CRITICAL
Network
|
google
|
android
|
While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL commands there is no mutex lock of allocated memory. If one thread sends an ioctl cm…
|
CWE-416
Use After Free
|
CVE-2017-14877
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253407
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-18, if the value param_buf->num_debug_register received from the F…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14883
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253408
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter params->entries[i].vfe_intf comes from userspace without any bounds check which c…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-14876
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253409
|
7.5 |
HIGH
Network
|
google
|
android
|
In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a heap overread vulnerability exists.
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2017-14875
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253410
|
9.8 |
CRITICAL
Network
|
qualcomm
|
sd_625_firmware sd_650_firmware sd_652_firmware sd_835_firmware
|
In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client structure can result in a Use After Free condition.
|
CWE-416
Use After Free
|
CVE-2017-14915
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|