|
247831
|
7.0 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a…
|
CWE-119 CWE-362 CWE-772
Incorrect Access of Indexable Resource ('Range Error') Race Condition Missing Release of Resource after Effective Lifetime
|
CVE-2017-8280
|
2024-11-21 12:33 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247832
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, while reading audio data from an unspecified driver, a buffer overflow or integer overflow could occur.
|
CWE-190 CWE-120
Integer Overflow or Wraparound Classic Buffer Overflow
|
CVE-2017-8278
|
2024-11-21 12:33 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247833
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_dba_register_client, if the client registers failed, it would be freed. However the client was not …
|
CWE-416
Use After Free
|
CVE-2017-8277
|
2024-11-21 12:33 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247834
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cmd & msm_isp_stats_update_cgc_override, 'stream_cfg_cmd->num_streams' is not che…
|
CWE-129
Improper Validation of Array Index
|
CVE-2017-8251
|
2024-11-21 12:33 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247835
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overf…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-8250
|
2024-11-21 12:33 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247836
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once. This would l…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-8247
|
2024-11-21 12:33 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247837
|
9.8 |
CRITICAL
Network
|
emc
|
appsync
|
EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
|
CWE-89
SQL Injection
|
CVE-2017-8015
|
2024-11-21 12:33 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247838
|
6.1 |
MEDIUM
Network
|
vmware
|
single_sign-on_for_pivotal_cloud_foundry
|
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputt…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8041
|
2024-11-21 12:33 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247839
|
6.5 |
MEDIUM
Network
|
vmware
|
single_sign-on_for_pivotal_cloud_foundry
|
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service das…
|
CWE-611
XXE
|
CVE-2017-8040
|
2024-11-21 12:33 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247840
|
9.8 |
CRITICAL
Network
|
qemu
|
qemu
|
Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8380
|
2024-11-21 12:33 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|