CVE-2018-6246
https://notcve.org/view.php?id=CVE-2018-6246
In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosure. This issue is rated as moderate. Android: A-69383916. Reference: N-CVE-2018-6246. En Android antes del nivel de seguridad del 2018-05-05, NVIDIA Widevine Trustlet contiene una vulnerabilidad en Widevine TA en la que el software lee datos más allá del final, o antes del inicio, del búfer planeado, lo que podría desembocar en la divulgación de información. • https://source.android.com/security/bulletin/pixel/2018-05-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-0900
https://notcve.org/view.php?id=CVE-2014-0900
The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure. El código Device Administrator en Android, en versiones anteriores a la 4.4.1_r1, podría permitir que los atacantes suplanten administradores de dispositivo y, consecuentemente, omitan las restricciones MDM aprovechando el error a la hora de actualizar la estructura de datos mAdminMap. • https://securityintelligence.com/how-to-cheat-your-mdm-compliance-without-a-password • CWE-20: Improper Input Validation •
CVE-2017-0845
https://notcve.org/view.php?id=CVE-2017-0845
A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35028827. Existe una vulnerabilidad de denegación de servicio en el framework de Android (syncstorageengine). • https://source.android.com/security/bulletin/pixel/2017-11-01 • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2017-0848
https://notcve.org/view.php?id=CVE-2017-0848
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64477217. Existe una vulnerabilidad de divulgación de información en el media framework de Android (libeffects). • https://source.android.com/security/bulletin/pixel/2017-11-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-0851
https://notcve.org/view.php?id=CVE-2017-0851
An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-35430570. Existe una vulnerabilidad de revelación de información en el media framework de Android (libhevc). • https://source.android.com/security/bulletin/pixel/2017-11-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •