|
253411
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware sd_625_firmware sd_650_firmware sd_652_firmware sd_835_firmware sd_845_firmware
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, SD 625, SD 650/52, SD 835, SD 845, DDR address input validation is being improperly truncated.
|
CWE-20
Improper Input Validation
|
CVE-2017-14913
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253412
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_400_firmware sd_410_firmware sd_412_firmware sd_4…
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile [VERSION]: MDM9206, MDM9607, MDM9650, MSM8909W, SD 200, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/S…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14912
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253413
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware apq8096au_firmware msm8996au_firmware mdm9650_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_430_firmware sd_625_firmware s…
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 625, SD 650/52, SD 8…
|
CWE-287
Improper Authentication
|
CVE-2017-14911
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253414
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.
|
NVD-CWE-noinfo
|
CVE-2017-14906
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253415
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to the lack of a range check on the array index into the WMI descriptor pool, arbit…
|
CWE-129
Improper Validation of Array Index
|
CVE-2017-14889
|
2024-11-21 12:13 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253416
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of messages of type eWNI_SME_MODIFY_ADDITIONAL_IES, an integer overfl…
|
CWE-119 CWE-190
Incorrect Access of Indexable Resource ('Range Error') Integer Overflow or Wraparound
|
CVE-2017-14887
|
2024-11-21 12:13 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253417
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor…
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2017-14882
|
2024-11-21 12:13 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253418
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to copy data has a size of only 8 bits and can be excee…
|
CWE-20
Improper Input Validation
|
CVE-2017-14878
|
2024-11-21 12:13 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253419
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, wma_unified_link_peer_stats_event_handler function has a variable num_rates which repre…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14885
|
2024-11-21 12:13 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253420
|
6.1 |
MEDIUM
Network
|
netiq
|
access_manager
|
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
|
CWE-601
Open Redirect
|
CVE-2017-14802
|
2024-11-21 12:13 |
2018-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|