Latest CVE Feed
-
7.8
HIGHCVE-2017-13193
In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the same sps being fed in over and over. This could lead to a remote denial of service of a critical system process with no additional exec... Read more
Affected Products : android- EPSS Score: %3.01
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13192
In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an infinite loop. This could lead to a remote denial of service of a critical system process with no additional executio... Read more
Affected Products : android- EPSS Score: %2.29
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13191
In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is no... Read more
Affected Products : android- EPSS Score: %2.29
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13190
A vulnerability in the Android media framework (libhevc) related to handling ps_codec_obj memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68299873.... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13189
A vulnerability in the Android media framework (libavc) related to handling dec_hdl memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68300072.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2017-13188
An information disclosure vulnerability in the Android media framework (aac). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65280786.... Read more
Affected Products : android- EPSS Score: %0.13
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2017-13187
An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65034175.... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13186
A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65735716.... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2017-13185
An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65123471.... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13184
In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyncInjector. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2017-13183
In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free due to a race condition if the user frees the buffer while it's being used in another thread. This could lead to a local elevation of privilege enabling c... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13182
In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution pri... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13181
In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer. This could lead to an local elevation of privilege enabling code execution as a privileged process with no additional execut... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-13180
In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing. This could lead to a local elevat... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-13179
In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free. Both ps_codec_obj and ps_create_op->s_ivd_create_op_t.pv_handle point to the same memory and ps_codec_obj could be... Read more
Affected Products : android- EPSS Score: %3.42
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-13178
In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails. This could lead to remote code execution as a privileged process with no additional execution privileges ... Read more
Affected Products : android- EPSS Score: %3.42
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-13177
In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions... Read more
Affected Products : android- EPSS Score: %10.05
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-13176
In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed... Read more
Affected Products : android- EPSS Score: %0.69
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-13108
DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.... Read more
Affected Products : dfndr_security- EPSS Score: %0.11
- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-13107
Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.... Read more
Affected Products : liveme- EPSS Score: %0.11
- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024