| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2017-13178 |
In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-66969281. Published: January 12, 2018; 6:29:00 PM -0500 |
V3.0: 9.8 CRITICAL V2.0: 10.0 HIGH |
| CVE-2017-13177 |
In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68320413. Published: January 12, 2018; 6:29:00 PM -0500 |
V3.0: 9.8 CRITICAL V2.0: 10.0 HIGH |
| CVE-2017-13176 |
In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964. Published: January 12, 2018; 6:29:00 PM -0500 |
V3.0: 8.8 HIGH V2.0: 9.3 HIGH |
| CVE-2017-0855 |
In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64452857. Published: January 12, 2018; 6:29:00 PM -0500 |
V3.0: 7.5 HIGH V2.0: 7.8 HIGH |
| CVE-2017-0846 |
An information disclosure vulnerability in the Android framework (clipboardservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64934810. Published: January 12, 2018; 6:29:00 PM -0500 |
V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2017-13160 |
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-37160362. Published: December 06, 2017; 9:29:01 AM -0500 |
V3.0: 9.8 CRITICAL V2.0: 10.0 HIGH |
| CVE-2017-13159 |
An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-32879772. Published: December 06, 2017; 9:29:01 AM -0500 |
V3.0: 7.5 HIGH V2.0: 7.8 HIGH |
| CVE-2017-13158 |
An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-32879915. Published: December 06, 2017; 9:29:01 AM -0500 |
V3.0: 7.5 HIGH V2.0: 7.8 HIGH |
| CVE-2017-13157 |
An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-32990341. Published: December 06, 2017; 9:29:01 AM -0500 |
V3.0: 7.5 HIGH V2.0: 7.8 HIGH |
| CVE-2017-13156 |
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847. Published: December 06, 2017; 9:29:01 AM -0500 |
V3.0: 7.8 HIGH V2.0: 7.2 HIGH |
| CVE-2017-13154 |
An elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63666573. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 7.8 HIGH V2.0: 7.2 HIGH |
| CVE-2017-13153 |
An elevation of privilege vulnerability in the Android media framework (libaudioservice). Product: Android. Versions: 8.0. Android ID A-65280854. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 7.8 HIGH V2.0: 7.2 HIGH |
| CVE-2017-13152 |
An information disclosure vulnerability in the Android media framework (libmedia drm). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-62872384. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2017-13151 |
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63874456. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 8.8 HIGH V2.0: 9.3 HIGH |
| CVE-2017-13150 |
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-38328132. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 9.1 CRITICAL V2.0: 8.5 HIGH |
| CVE-2017-13149 |
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65719872. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 9.1 CRITICAL V2.0: 8.5 HIGH |
| CVE-2017-13148 |
A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65717533. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 6.5 MEDIUM V2.0: 7.1 HIGH |
| CVE-2017-0880 |
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID A-65646012. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 6.5 MEDIUM V2.0: 7.1 HIGH |
| CVE-2017-0879 |
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65025028. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 9.1 CRITICAL V2.0: 8.5 HIGH |
| CVE-2017-0878 |
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291. Published: December 06, 2017; 9:29:00 AM -0500 |
V3.0: 8.8 HIGH V2.0: 9.3 HIGH |