Vulnerability index

Browse CVEs

388 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Android HIGH 7.8
CVE-2018-11304

Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all …

Fix: after 8.1
Fix from $1,950 2018-07-06
Android HIGH 7.8
CVE-2018-5898

Integer overflow can occur in msm_pcm_adsp_stream_cmd_put() function if the user supplied data "param_length" goes beyond certain limit in Android re…

Mitigation only
Fix from $1,950 2018-07-06
Android HIGH 7.5
CVE-2018-3577

While processing fragments, when the fragment count becomes very large, an integer overflow leading to a buffer overflow can occur in Android release…

Patch available
Fix from $1,950 2018-07-06
Android HIGH 7.8
CVE-2017-15854

The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma_radio_chan_stats_event_handl…

Patch available
Fix from $1,950 2018-06-12
Android HIGH 7.8
CVE-2017-18070

In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rs…

Patch available
Fix from $1,950 2018-06-12
Android HIGH 7.8
CVE-2017-6290

In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which …

Mitigation only
Fix from $1,950 2018-06-07
Android HIGH 7.3
CVE-2018-5820

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch leve…

Mitigation only
Fix from $1,950 2018-04-03
Android HIGH 7.3
CVE-2017-15836

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch leve…

Mitigation only
Fix from $1,950 2018-04-03
Android CRITICAL 9.8
CVE-2017-17766

In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firm…

Patch available
Fix from $2,300 2018-03-30
Android HIGH 7.8
CVE-2017-14887

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of messages of type…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.8
CVE-2017-15831

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the function wma_ndp_end_indicatio…

Patch available
Fix from $1,950 2018-03-16
Android CRITICAL 9.8
CVE-2016-10393

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a clip with large siz…

Mitigation only
Fix from $2,300 2018-03-15
Android HIGH 7.8
CVE-2017-15862

In all Qualcomm products with Android releases from CAF using the Linux kernel, in wma_unified_link_radio_stats_event_handler(), the number of radio …

Mitigation only
Fix from $1,950 2018-02-23
Android HIGH 7.8
CVE-2017-17764

In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in…

Mitigation only
Fix from $1,950 2018-02-23
Android HIGH 7.8
CVE-2017-17765

In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in …

Mitigation only
Fix from $1,950 2018-02-23
Chrome HIGH 8.8
CVE-2017-5130

An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attac…

Fix: 2.9.5 / 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5131

An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Android HIGH 7.8
CVE-2017-13182

In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write. This could lead to a loc…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-0869

NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elevation of privilege enabling c…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-11043

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a WiFI driver function, an integer…

Patch available
Fix from $1,950 2017-12-05
Android HIGH 7.8
CVE-2017-0841

A remote code execution vulnerability in the Android system (libutils). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0.…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11085

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an integer overflow leading to a buff…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-9690

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a qbt1000 ioctl handler, an incorr…

Patch available
Fix from $1,950 2017-11-16
Chrome HIGH 8.8
CVE-2017-5063

A numeric overflow in Skia in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacke…

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,950 2017-10-27
Android HIGH 7.8
CVE-2017-9683

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a meta image, an integ…

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.8
CVE-2015-1537

Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code via a crafted application.

Fix: after 4.4.4
Fix from $1,950 2017-09-28
Android MEDIUM 5.5
CVE-2015-1526

The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.

Fix: after 4.4.4
Fix from $1,600 2017-09-28
Android HIGH 7.8
CVE-2017-8250

In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed ac…

Fix: after 8.0
Fix from $1,950 2017-09-21
Android HIGH 7.8
CVE-2017-8278

In all Qualcomm products with Android releases from CAF using the Linux kernel, while reading audio data from an unspecified driver, a buffer overflo…

Fix: after 8.0
Fix from $1,950 2017-09-21
Android HIGH 7.8
CVE-2015-1527

Integer overflow in IAudioPolicyService.cpp in Android allows local users to gain privileges via a crafted application, aka Android Bug ID 19261727.

Patch available
Fix from $1,950 2017-09-15