CVE-2017-13177
https://notcve.org/view.php?id=CVE-2017-13177
In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. • http://www.securityfocus.com/bid/102414 http://www.securitytracker.com/id/1040106 https://source.android.com/security/bulletin/2018-01-01 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2017-13157
https://notcve.org/view.php?id=CVE-2017-13157
An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-32990341. Existe una vulnerabilidad de divulgación de información en el sistema de Android (activitymanagerservice). • http://www.securityfocus.com/bid/102109 https://source.android.com/security/bulletin/2017-12-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-0873
https://notcve.org/view.php?id=CVE-2017-0873
A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63316255. Existe una vulnerabilidad de denegación de servicio en el framework multimedia de Android (libmpeg2). • http://www.securityfocus.com/bid/102126 https://source.android.com/security/bulletin/2017-12-01 • CWE-20: Improper Input Validation •
CVE-2017-0876
https://notcve.org/view.php?id=CVE-2017-0876
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-64964675. Existe una vulnerabilidad de ejecución remota de código en el framework multimedia de Android (libavc). • http://www.securityfocus.com/bid/102126 https://source.android.com/security/bulletin/2017-12-01 • CWE-20: Improper Input Validation •
CVE-2017-13158
https://notcve.org/view.php?id=CVE-2017-13158
An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-32879915. Existe una vulnerabilidad de divulgación de información en el sistema de Android (activitymanagerservice). • http://www.securityfocus.com/bid/102109 https://source.android.com/security/bulletin/2017-12-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •