Google Latest Vulnerabilities

December 18

Heap Corruption Vulnerability in V8 Prior to 131.0.6778.204

CVE-2024-12692
GoogleChrome

CVE-2024-12694
GoogleChrome

Attackers Can Execute Arbitrary Code in Chrome Sandbox Via Crafted HTML Page

CVE-2024-12693
GoogleChrome

CVE-2024-12695
GoogleChrome

December 13

Google Web Stories Vulnerable to Stored XSS

CVE-2024-54317
GoogleWeb Stories6.5MEDIUM

December 12

Type Confusion Vulnerability in Google Chrome Prior to 131.0.6778.139

CVE-2024-12381
GoogleChrome8.8HIGH

Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed remote attacker to potentially exploit heap corruption via crafted HTML page (Chromium security severity: High)

CVE-2024-12382
GoogleChrome8.8HIGH

December 5

Possible Out of Bounds Write in gps_hal Could Lead to Local Escalation of Privilege

CVE-2018-9391
GoogleAndroid6.7MEDIUM

Possible Out-of-Bounds Read Vulnerability in gl_proc.c Could Lead to Local Escalation of Privilege

CVE-2018-9390
GoogleAndroid6.7MEDIUM

Obedient Pixels Shudder Before Mighty Lord of Pointy Clicky Things

CVE-2018-9388
GoogleAndroid9.8CRITICAL

Possible Stack Buffer Overflow in HTC Reboot Block Driver

CVE-2018-9386
GoogleAndroid6.7MEDIUM

Possible Buffer Overflow in mtk_ts_Abts.c Leads to Local Escalation of Privilege

CVE-2017-13308
GoogleAndroid6.7MEDIUM

Stack Buffer Overflow Vulnerability in flp2hal Could Lead to Local Escalation of Privilege

CVE-2018-9403
GoogleAndroid6.7MEDIUM

Kernel Buffer Overwrite Vulnerability

CVE-2018-9402
GoogleAndroid7.8HIGH

Possible Out of Bounds Write in sw49408 IRQ Runtime Engine Could Lead to Local Escalation of Privilege

CVE-2018-9463
GoogleAndroid6.7MEDIUM

Possible OOB Write in Mediatek FM Radio Driver could lead to Local Escalation of Privilege

CVE-2018-9398
GoogleAndroid6.7MEDIUM

Possible Out of Bounds Write in ftm4_pdc.c Could Lead to Local Escalation of Privilege

CVE-2018-9462
GoogleAndroid6.7MEDIUM

Possible Use-After-Free Vulnerability in af_packet.c Leads to Local Escalation of Privilege

CVE-2018-9439
GoogleAndroid6.7MEDIUM

Possible Local Escalation of Privilege Through Out of Bounds Writes

CVE-2018-9399
GoogleAndroid6.7MEDIUM

Information Disclosure Due to Missing Bounds Check in emmc_rpmb.c

CVE-2018-9407
GoogleAndroid5.5MEDIUM

Possible Memory Corruption Leading to Local Escalation of Privilege

CVE-2018-9416
GoogleAndroid6.7MEDIUM

Potential OOB Write Vulnerability in MTK WMT Device Driver Could Lead to Local Escalation of Privilege

CVE-2018-9397
GoogleAndroid6.7MEDIUM

Possible Out of Bounds Write in ril.cpp Could Lead to Local Escalation of Privilege

CVE-2018-9404
GoogleAndroid6.7MEDIUM

Potential OOB write in drivers/input/touchscreen/mediatek/GT1151/gt1x_generic.c and gt1x_tools.c may lead to local escalation of privilege

CVE-2018-9400
GoogleAndroid6.7MEDIUM

Missing Bounds Check Leads to Local Information Disclosure with System Execution Privileges

CVE-2018-9408
GoogleAndroid4.4MEDIUM

December 4

Possible Out of Bounds Write in rpc_msg_handler and Related Handlers of Meditek ECCCI Could Lead to Local Escalation of Privilege

CVE-2018-9396
GoogleAndroid6.7MEDIUM

Possible OOB Write Vulnerability in mtk_cfg80211_vendor_packet_keep_alive_start Could Lead to Local Escalation of Privilege

CVE-2018-9395
GoogleAndroid6.7MEDIUM

Possible OOB write vulnerability in mtk_p2p_wext_set_key

CVE-2018-9394
GoogleAndroid6.7MEDIUM

Possible OOB Write Vulnerability in Mediatek WLAN Driver Could Lead to Local Escalation of Privilege

CVE-2018-9393
GoogleAndroid6.7MEDIUM

Possible out of bounds write in GPS HAL could lead to local escalation of privilege

CVE-2018-9392
GoogleAndroid6.7MEDIUM

December 3

type confusion in Chrome prior to 131.0.6778.108

CVE-2024-12053
GoogleChrome

Possible Out-of-Bounds Read Vulnerability in sdp_copy_raw_data

CVE-2018-9441
GoogleAndroid5.5MEDIUM

Possible Out of Bound Read Vulnerability in SDP Discovery's process_service_search_attr_rsp

CVE-2018-9449
GoogleAndroid5.5MEDIUM

December 2

Possible Out of Bound Read Leads to Local Information Disclosure Without Additional Execution Privileges

CVE-2018-9435
GoogleAndroid5.5MEDIUM

Possible Escalation of Privilege Vulnerability in OSUInfo.java

CVE-2018-9431
GoogleAndroid7.8HIGH

Possible Out of Bounds Write in btif_storage's prop2cfg Could Lead to Remote Code Execution

CVE-2018-9430
GoogleAndroid9.8CRITICAL

Possible Out of Bound Read in ItemTable.cpp Could Lead to Information Disclosure

CVE-2018-9429
GoogleAndroid6.5MEDIUM

Incorrect Implementation in RSA Key Pair Generator Could Lead to Weak RSA Keys and Crypto Vulnerabilities

CVE-2018-9426
GoogleAndroid7.5HIGH

Possible Out of Bound Read Vulnerability in IHEVCD_parse_slice_header Could Lead to Denial of Service

CVE-2018-9423
GoogleAndroid6.5MEDIUM

Possible Stack Buffer Overflow in dtif_rc.cc Leads to Remote Code Execution

CVE-2018-9418
GoogleAndroid9.8CRITICAL

Possible Out of Bounds Write in gattServerSendResponseNative Could Lead to Local Escalation of Privilege

CVE-2018-9414
GoogleAndroid7.8HIGH

Potential Out of Bounds Write in BTIF's btif_rc.cc Could Lead to Remote Code Execution

CVE-2018-9413
GoogleAndroid8.8HIGH

Possible OOBE Write Vulnerability in Meditate's Port RPC Handlers

CVE-2018-9376
GoogleAndroid6.7MEDIUM

Potential Information Disclosure Vulnerability in gatt_sr.c

CVE-2018-9381
GoogleAndroid7.5HIGH

Possible Out of Bounds Write in l2c_lcc_proc_pdu Could Lead to Remote Escalation of Privilege

CVE-2018-9380
GoogleAndroid8.8HIGH

November 28

Possible Information Disclosure through Uninitialized Data

CVE-2018-9377
GoogleAndroid5.5MEDIUM

Possible Permissions Bypass in Package Manager

CVE-2018-9374
GoogleAndroid7.8HIGH

November 27

Possible Remote Denial of Service Vulnerability in VideoFrameScheduler::PLL::fit

CVE-2018-9354
GoogleAndroid6.5MEDIUM

Possible Heap Buffer Out of Bound Read Leading to Remote Denial of Service

CVE-2018-9353
GoogleAndroid6.5MEDIUM

Possible Resource Exhaustion in ihevcd_allocate_dynamic_bufs Could Lead to Remote Denial of Service

CVE-2018-9352
GoogleAndroid6.5MEDIUM

Possibly Unbound Read Could Lead to Remote Denial of Service

CVE-2018-9351
GoogleAndroid6.5MEDIUM

Possible Out of Bound Read Vulnerability in ih264d_utils.c Could Lead to Denial of Service

CVE-2018-9350
GoogleAndroid6.5MEDIUM

Possible Out of Bounds Read in mcomp.c Could Lead to Denial of Service

CVE-2018-9349
GoogleAndroid6.5MEDIUM

Possible Out of Bounds Write in String16.cpp Could Lead to Local Escalation of Privilege

CVE-2017-13323
GoogleAndroid7.8HIGH

Possibility of Local Information Disclosure in SensorService

CVE-2017-13321
GoogleAndroid5.5MEDIUM

Possible OOB Read Vulnerability in MPEG2Dec Could Lead to Remote DoS

CVE-2017-13320
GoogleAndroid6.5MEDIUM

Possible Buffer Overread in pvmp3_get_main_data_size Could Lead to Remote Information Disclosure

CVE-2017-13319
GoogleAndroid7.5HIGH

Possible Permissions Bypass in RecognitionService.java Leads to Local Escalation of Privilege

CVE-2017-13316
GoogleAndroid7.8HIGH

November 20

Possible Blocking of Internet Traffic Through VPN Due to Bad UID Check

CVE-2018-9487
GoogleAndroid5.5MEDIUM

Possible Out of Bounds Read Leads to Local Information Disclosure Over Bluetooth

CVE-2018-9486
GoogleAndroid6.5MEDIUM

Possible Out of Bounds Read in l2cble_process_sig_cmd Could Lead to Remote Information Disclosure

CVE-2018-9485
GoogleAndroid6.5MEDIUM

Possible Out of Bounds Read Leads to Remote Information Disclosure

CVE-2018-9484
GoogleAndroid7.5HIGH

Possible Out of Bounds Read Leads to Remote Information Disclosure in BTA_DM

CVE-2018-9483
GoogleAndroid6.5MEDIUM

Possible Out of Bounds Read in BTIF HD Could Lead to Local Information Disclosure

CVE-2018-9482
GoogleAndroid6.5MEDIUM

Possible Out-of-Bounds Read Leads to Remote Information Disclosure

CVE-2018-9481
GoogleAndroid6.5MEDIUM

Possible Out-of-Bounds Read in BTA's bta_hd_get_report_act Could Lead to Remote Information Disclosure

CVE-2018-9480
GoogleAndroid6.5MEDIUM

Out of Bounds Write Vulnerability in sdp_server.cc Could Lead to Remote Code Execution

CVE-2018-9479
GoogleAndroid9.8CRITICAL

Out of Bounds Write Vulnerability in SecureDrop Server Could Lead to Remote Code Execution

CVE-2018-9478
GoogleAndroid9.8CRITICAL

Possible Authentication Bypass in Settings App

CVE-2018-9477
GoogleAndroid7.8HIGH

Possible Out of Bounds Stack Write in Bluetooth Function Could Lead to Remote Escalation of Privilege

CVE-2018-9475
GoogleAndroid8.8HIGH

Possible Serialization/Deserialization Mismatch in MediaPlayer.java Could Lead to Local Escalation of Privilege

CVE-2018-9474
GoogleAndroid7.8HIGH

Possible Out-of-Bounds Write in xmlMemStrdupLoc Could Lead to Remote Code Execution

CVE-2018-9472
GoogleAndroid8.8HIGH

Loss of Data through Deserialization: A Local Escalation of Privilege Threat

CVE-2018-9471
GoogleAndroid7.8HIGH

Potential Out-of-Bounds Write in BFF Scanner Could Lead to Remote Escalation of Privilege

CVE-2018-9470
GoogleAndroid8.8HIGH

Possible Spoofed Shortcut Creation in ShortcutService.java Leads to Local Escalation of Privilege

CVE-2018-9469
GoogleAndroid7.8HIGH

Possible Read/Write of Arbitrary Files Through Permissions Bypass

CVE-2018-9468
GoogleAndroid7.1HIGH

Code Execution Vulnerability in CarAppService Deserialization Logic

CVE-2024-10382
GoogleAndroid

Incorrect Web Origin Determination in UriTest.java Could Lead to Security Breaches

CVE-2018-9467
GoogleAndroid9.8CRITICAL

November 19

Possible Out of Bounds Write in valid.c Could Lead to Remote Escalation of Privilege

CVE-2018-9466
GoogleAndroid8.8HIGH

Possible Out of Bounds Read Vulnerability in Sdp_utils

CVE-2018-9456
GoogleAndroid7.5HIGH

Possible Resource Exhaustion in M3UParser.cpp Leads to Denial of Service

CVE-2018-9440
GoogleAndroid6.5MEDIUM

Remote Code Execution Vulnerability in Builtins' ArrayConcatVisitor

CVE-2018-9433
GoogleAndroid8.8HIGH

Potential Permissions Bypass in BluetoothPermissionActivity

CVE-2018-9432
GoogleAndroid7.8HIGH

Possible Out of Bounds Write in AAudioServiceStreamBase Could Lead to Local Arbitrary Code Execution

CVE-2018-9428
GoogleAndroid7.8HIGH

Possible Out-of-Bounds Write in CryptoPlugin::decrypt Could Lead to Local Escalation of Privilege

CVE-2018-9424
GoogleAndroid7.8HIGH

Possible Information Leak in Binder due to Uninitialized Data

CVE-2018-9421
GoogleAndroid5.5MEDIUM

Possible Information Disclosure in BnCameraService::onTransact

CVE-2018-9420
GoogleAndroid5.5MEDIUM

Possible Out of Bounds Read Vulnerability in l2cble_process_sig_cmd Could Lead to Remote Information Disclosure

CVE-2018-9419
GoogleAndroid7.5HIGH

Possible Use-After-Free Vulnerability in f_hid.c could lead to Local Escalation of Privilege

CVE-2018-9417
GoogleAndroid7.8HIGH

Possible Resource Exhaustion in ID3.cpp May Lead to Denial of Service

CVE-2018-9412
GoogleAndroid5.5MEDIUM

Possible Out-of-Bounds Write in ClearKeyCasPlugin.cpp Could Lead to Remote Arbitrary Code Execution

CVE-2018-9411
GoogleAndroid8.8HIGH

Possible Out of Bounds Read in FontUtils.cpp Could Lead to Local Information Disclosure

CVE-2018-9410
GoogleAndroid5.5MEDIUM

Possible Out of Bounds Read and Code Execution Vulnerability in smp_l2c.cc

CVE-2018-9365
GoogleAndrioid8.8HIGH

Possible Out of Bounds Write in HWCSession::SetColorModeById Could Lead to Local Escalation of Privilege

CVE-2018-9409
GoogleAndroid

Potential Out-of-Bounds Write in cmd_flash_mmc_sparse_img Could Lead to Local Escalation of Privilege

CVE-2018-9372
GoogleAndroid

Mediatek Preloader Vulnerable to Out-of-Bounds Reads and Writes

CVE-2018-9371
GoogleAndroid6.4MEDIUM

Memory Corruption Vulnerability in Download.c Leads to Local Escalation of Privilege

CVE-2018-9370
GoogleAndroid7.3HIGH

Local Escalation of Privilege Vulnerability

CVE-2018-9369
GoogleAndroid7.3HIGH

Possible Local Escalation of Privilege via Arbitrary Kernel Memory Write in mtkscoaudio debugfs

CVE-2018-9368
GoogleAndroid7.8HIGH

Possible Out of Bounds Write Vulnerability in FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS

CVE-2018-9367
GoogleAndroid7.8HIGH