Show filters
782 Total Results
Displaying 61-70 of 782
Sort by:
Attacker Value
Unknown

CVE-2018-9365

Disclosure Date: November 19, 2024 (last updated December 19, 2024)
In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2018-9348

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2018-9346

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2018-9345

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2018-9341

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Attacker Value
Unknown

CVE-2018-9340

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.
Attacker Value
Unknown

CVE-2018-9339

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2018-9338

Disclosure Date: November 19, 2024 (last updated January 05, 2025)
In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13315

Disclosure Date: November 19, 2024 (last updated December 19, 2024)
In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2017-13314

Disclosure Date: November 15, 2024 (last updated December 19, 2024)
In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the VPN networks, with no additional execution privileges needed. User interaction is not needed for exploitation.