CVE-2017-13228
https://notcve.org/view.php?id=CVE-2017-13228
In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. • http://www.securityfocus.com/bid/102976 https://source.android.com/security/bulletin/2018-02-01 • CWE-787: Out-of-bounds Write •
CVE-2017-13230
https://notcve.org/view.php?id=CVE-2017-13230
In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. • http://www.securityfocus.com/bid/102976 https://source.android.com/security/bulletin/2018-02-01 • CWE-787: Out-of-bounds Write •
CVE-2017-13243 – Android OS FLAG_SECURE Information Disclosure
https://notcve.org/view.php?id=CVE-2017-13243
A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. ID: A-38258991. Existe una vulnerabilidad de divulgación de información en el sistema de Android (ui). • http://www.securityfocus.com/bid/103013 https://source.android.com/security/bulletin/pixel/2018-02-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-13233
https://notcve.org/view.php?id=CVE-2017-13233
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. • http://www.securityfocus.com/bid/102976 https://source.android.com/security/bulletin/2018-02-01 • CWE-400: Uncontrolled Resource Consumption •
CVE-2017-13234
https://notcve.org/view.php?id=CVE-2017-13234
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. • http://www.securityfocus.com/bid/102976 https://source.android.com/security/bulletin/2018-02-01 • CWE-772: Missing Release of Resource after Effective Lifetime •