| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-0663 | Hig | 0.51 | 7.8 | 0.02 | Jun 14, 2017 | A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that… | ||
| CVE-2017-0649 | Hig | 0.46 | 7.0 | 0.01 | Jun 14, 2017 | An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and because of… | ||
| CVE-2017-0648 | Hig | 0.51 | 7.8 | 0.02 | Jun 14, 2017 | An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of a local permanent device compromise, which may require… | ||
| CVE-2017-0638 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2017 | A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary code execution in an… | ||
| CVE-2017-0637 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2017 | A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the… | ||
| CVE-2017-0636 | Hig | 0.46 | 7.0 | 0.01 | Jun 14, 2017 | An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product:… | ||
| CVE-2017-8241 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a WLAN function due to an incorrect message length. | ||
| CVE-2017-8240 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability. | ||
| CVE-2017-8238 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a camera function. | ||
| CVE-2017-8237 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists while loading a firmware image. | ||
| CVE-2017-8236 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an IPA driver. | ||
| CVE-2017-8234 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function. | ||
| CVE-2017-8233 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In a camera driver function in all Android releases from CAF using the Linux kernel, a bounds check is missing when writing into an array potentially leading to an out-of-bounds heap write. | ||
| CVE-2017-7373 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver. | ||
| CVE-2017-7372 | Hig | 0.46 | 7.0 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location. | ||
| CVE-2017-7371 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a data pointer is potentially used after it has been freed when SLIMbus is turned off by Bluetooth. | ||
| CVE-2017-7370 | Hig | 0.46 | 7.0 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition. | ||
| CVE-2017-7369 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel stack corruption. | ||
| CVE-2017-7368 | Hig | 0.46 | 7.0 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver. | ||
| CVE-2017-7367 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an integer underflow vulnerability exists while processing the boot image. | ||
| CVE-2017-7365 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overread can occur if a particular string is not NULL terminated. | ||
| CVE-2016-10342 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler. | ||
| CVE-2016-10341 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended. | ||
| CVE-2016-10340 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler. | ||
| CVE-2016-10339 | Hig | 0.46 | 7.1 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore. | ||
| CVE-2016-10338 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing. | ||
| CVE-2015-9033 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer. | ||
| CVE-2015-9030 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication. | ||
| CVE-2015-9029 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory. | ||
| CVE-2015-9028 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine. | ||
| CVE-2015-9027 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM. | ||
| CVE-2015-9026 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM. | ||
| CVE-2015-9025 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application. | ||
| CVE-2015-9023 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API. | ||
| CVE-2015-9022 | Hig | 0.46 | 7.0 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs. | ||
| CVE-2015-9020 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory. | ||
| CVE-2014-9967 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM. | ||
| CVE-2014-9966 | Hig | 0.46 | 7.0 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display. | ||
| CVE-2014-9965 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call. | ||
| CVE-2014-9964 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality. | ||
| CVE-2014-9963 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WideVine DRM. | ||
| CVE-2014-9962 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command. | ||
| CVE-2014-9961 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection. | ||
| CVE-2014-9960 | Hig | 0.51 | 7.8 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API. | ||
| CVE-2016-9984 | Hig | 0.57 | 8.8 | 0.02 | Jun 13, 2017 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276. | ||
| CVE-2017-9603 | Hig | 0.61 | 8.8 | 0.05 | Jun 13, 2017 | SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php. | ||
| CVE-2017-9429 | Hig | 0.60 | 8.8 | 0.03 | Jun 13, 2017 | SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php. | ||
| CVE-2016-5391 | Hig | 0.49 | 7.5 | 0.03 | Jun 13, 2017 | libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart). | ||
| CVE-2016-3704 | Hig | 0.49 | 7.5 | 0.02 | Jun 13, 2017 | Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords. | ||
| CVE-2015-4596 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2017 | Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges. |
- risk 0.51cvss 7.8epss 0.02
A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and because of…
- risk 0.51cvss 7.8epss 0.02
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of a local permanent device compromise, which may require…
- risk 0.51cvss 7.8epss 0.01
A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary code execution in an…
- risk 0.51cvss 7.8epss 0.01
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the MediaTek command queue driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product:…
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a WLAN function due to an incorrect message length.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a camera function.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists while loading a firmware image.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an IPA driver.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function.
- risk 0.51cvss 7.8epss 0.00
In a camera driver function in all Android releases from CAF using the Linux kernel, a bounds check is missing when writing into an array potentially leading to an out-of-bounds heap write.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver.
- risk 0.46cvss 7.0epss 0.00
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a data pointer is potentially used after it has been freed when SLIMbus is turned off by Bluetooth.
- risk 0.46cvss 7.0epss 0.00
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel stack corruption.
- risk 0.46cvss 7.0epss 0.00
In all Android releases from CAF using the Linux kernel, a race condition potentially exists in the ioctl handler of a sound driver.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, an integer underflow vulnerability exists while processing the boot image.
- risk 0.51cvss 7.8epss 0.00
In all Android releases from CAF using the Linux kernel, a buffer overread can occur if a particular string is not NULL terminated.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.
- risk 0.46cvss 7.1epss 0.01
In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.
- risk 0.46cvss 7.0epss 0.00
In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
- risk 0.46cvss 7.0epss 0.00
In all Android releases from CAF using the Linux kernel, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists in Secure Display.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WideVine DRM.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection.
- risk 0.51cvss 7.8epss 0.01
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the PlayReady API.
- risk 0.57cvss 8.8epss 0.02
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.
- risk 0.61cvss 8.8epss 0.05
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.
- risk 0.60cvss 8.8epss 0.03
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.
- risk 0.49cvss 7.5epss 0.03
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
- risk 0.49cvss 7.5epss 0.02
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
- risk 0.51cvss 7.8epss 0.00
Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.