|
198801
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
|
CWE-200
Information Exposure
|
CVE-2017-11040
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198802
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11002
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198803
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
|
CWE-200
Information Exposure
|
CVE-2017-11001
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198804
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11000
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198805
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing …
|
CWE-119 NVD-CWE-noinfo
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10999
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198806
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10998
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198807
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10997
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198808
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fa…
|
CWE-200
Information Exposure
|
CVE-2017-10996
|
2024-11-21 12:06 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198809
|
8.8 |
HIGH
Network
|
ruby-lang
|
ruby
|
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log an…
|
CWE-287
Improper Authentication
|
CVE-2017-10784
|
2024-11-21 12:06 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198810
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.
|
CWE-20
Improper Input Validation
|
CVE-2017-10700
|
2024-11-21 12:06 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|