CVE-2018-9458
https://notcve.org/view.php?id=CVE-2018-9458
In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing the user's keypresses while the screen was locked with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-71786287. En computeFocusedWindow de RootWindowContainer.java,y las funciones relacionadas, hay una posible interceptación de las pulsaciones de tecla debido a que se el foco se pone sobre la ventana incorrecta. • http://www.securitytracker.com/id/1041432 https://source.android.com/security/bulletin/2018-08-01 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •
CVE-2018-9437
https://notcve.org/view.php?id=CVE-2018-9437
In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78656554. En getstring de ID3.cpp, hay una posible lectura fuera de límites debido a la falta de una comprobación de límites. • http://www.securitytracker.com/id/1041432 https://source.android.com/security/bulletin/2018-08-01 • CWE-125: Out-of-bounds Read •
CVE-2018-9444
https://notcve.org/view.php?id=CVE-2018-9444
In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android ID: A-63521984. En ih264d_video_decode de ih264d_api.c, hay un posible agotamiento de recursos debido a un bucle infinito. • http://www.securitytracker.com/id/1041432 https://source.android.com/security/bulletin/2018-08-01 • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •
CVE-2018-9355
https://notcve.org/view.php?id=CVE-2018-9355
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74016921. En bta_dm_sdp_result de bta_dm_act.cc, hay una posible escritura en la pila fuera de límites debido a la falta de una comprobación de límites. • http://www.securityfocus.com/bid/104461 https://source.android.com/security/bulletin/2018-06-01 • CWE-787: Out-of-bounds Write •
CVE-2018-9455
https://notcve.org/view.php?id=CVE-2018-9455
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78136677. En sdpu_extract_attr_seq de sdp_utils.cc, hay una posible lectura fuera de límites debido a una comprobación de límites incorrecta. • http://www.securitytracker.com/id/1041432 https://source.android.com/security/bulletin/2018-08-01 • CWE-125: Out-of-bounds Read •