|
248241
|
6.1 |
MEDIUM
Network
|
ntop
|
ntopng
|
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7416
|
2024-11-21 12:31 |
2017-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248242
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver.
|
CWE-415
Double Free
|
CVE-2017-7373
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248243
|
7.0 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.
|
CWE-119 CWE-362
Incorrect Access of Indexable Resource ('Range Error') Race Condition
|
CVE-2017-7372
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248244
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a data pointer is potentially used after it has been freed when SLIMbus is turned off by Bluetooth.
|
CWE-416
Use After Free
|
CVE-2017-7371
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248245
|
7.0 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.
|
CWE-416
Use After Free
|
CVE-2017-7370
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248246
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel stack corruption.
|
CWE-20
Improper Input Validation
|
CVE-2017-7369
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248247
|
7.0 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.
|
CWE-362
Race Condition
|
CVE-2017-7368
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248248
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an integer underflow vulnerability exists while processing the boot image.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2017-7367
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248249
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.
|
CWE-20
Improper Input Validation
|
CVE-2017-7366
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248250
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a buffer overread can occur if a particular string is not NULL terminated.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-7365
|
2024-11-21 12:31 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|