CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-3596

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, legacy code vulnerable after migration has been removed.

    Published: 3 Apr 2018
    7.5
    High

    CVE-2018-3598

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, insufficient validation of parameters from userspace in the camera driver can lead to information leak and out-of-bounds access.

    Published: 3 Apr 2018
    7.3
    High

    CVE-2018-5822

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, compromised WLAN FW can potentially cause a buffer overwrite.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-5824

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing HTT_T2H_MSG_TYPE_RX_FLUSH or HTT_T2H_MSG_TYPE_RX_PN_IND messages, a buffer overflow can occur if the tid value obtained from the firmware is out of range.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-5825

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the kernel IPA driver, a Use After Free condition can occur.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-5828

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_extscan_start_stop_event_handler(), vdev_id comes from the variable event from firmware and is not properly validated potentially leading to a buffer overwrite.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2017-14880

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while IPA WAN-driver is processing multiple requests from modem/user-space module, the global variable "num_q6_rule" does not have a mutex lock and thus can be accessed and modified by multiple threads.

    Published: 3 Apr 2018
    7.3
    High

    CVE-2017-14894

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in wma_vdev_start_resp_handler(), vdev id is received from firmware as part of WMI_VDEV_START_RESP_EVENTID. This vdev id can be greater than max bssid stored in wma handle and this would result in buffer overwrite while accessing wma_handle->interfaces[vdev_id].

    Published: 3 Apr 2018
    9.8
    Critical

    CVE-2018-3599

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while notifying a DCI client, a Use After Free condition can occur.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2017-11075

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, if cmd_pkt and reg_pkt are called from different userspace threads, a use after free condition can potentially occur in wdsp_glink_write().

    Published: 3 Apr 2018
    7.3
    High

    CVE-2017-14890

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the processing of an SWBA event, the vdev_map value is not properly validated leading to a potential buffer overwrite in function wma_send_bcn_buf_ll().

    Published: 3 Apr 2018
    8.8
    High

    CVE-2017-15822

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing a 802.11 management frame, a buffer overflow may potentially occur.

    Published: 3 Apr 2018
    5.3
    Medium

    CVE-2017-15837

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a policy for the packet pattern attribute NL80211_PKTPAT_OFFSET is not defined which can lead to a buffer over-read in nla_get_u32().

    Published: 3 Apr 2018
    5.3
    Medium

    CVE-2017-15853

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing PTT commands, ptt_sock_send_msg_to_app() is invoked without validating the packet length. If the packet length is invalid, then a buffer over-read can occur.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2017-17770

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in a power driver ioctl handler, an Untrusted Pointer Dereference may potentially occur.

    Published: 3 Apr 2018
    7.3
    High

    CVE-2018-5820

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the function wma_tbttoffset_update_event_handler(), a parameter received from firmware is used to allocate memory for a local buffer and is not properly validated. This can potentially result in an integer overflow subsequently leading to a heap overwrite.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-5823

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, improper buffer length validation in extscan hotlist event can lead to potential buffer overflow.

    Published: 3 Apr 2018
    5.9
    Medium

    CVE-2018-5826

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, due to a race condition, a Use After Free condition can occur in the WLAN driver.

    Published: 3 Apr 2018
    9.8
    Critical

    CVE-2017-18147

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in MMCP, a downlink message is not being properly validated.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-3566

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overwrite may occur in ProcSetReqInternal() due to missing length check.

    Published: 3 Apr 2018
    7.3
    High

    CVE-2018-5821

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_wow_wakeup_host_event(), wake_info->vdev_id is received from FW and is used directly as array index to access wma->interfaces whose max index should be (max_bssid-1). If wake_info->vdev_id is greater than or equal to max_bssid, an out-of-bounds read occurs.

    Published: 3 Apr 2018
    5.5
    Medium

    CVE-2018-3689

    Last Modified: 21 Nov 2024

    AESM daemon in Intel Software Guard Extensions Platform Software Component for Linux before 2.1.102 can effectively be disabled by a local attacker creating a denial of services like remote attestation provided by the AESM.

    Published: 3 Apr 2018
    5.5
    Medium

    CVE-2016-8365

    Last Modified: 21 Nov 2024

    OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and including, Version 4.4; and PI Data Archive versions prior to PI Data Archive 2015, Version 3.4.395.64) operates between endpoints without a complete model of endpoint features potentially causing the product to perform actions based on this incomplete model, which could result in a denial of service. OSIsoft reports that in order to exploit the vulnerability an attacker would need to be locally connected to a server. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)

    Published: 3 Apr 2018
    7.5
    High

    CVE-2016-7472

    Last Modified: 21 Nov 2024

    F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS) via a crafted HTTP request.

    Published: 3 Apr 2018
    5.3
    Medium

    CVE-2018-8836

    Last Modified: 21 Nov 2024

    Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

    Published: 3 Apr 2018
    7
    High

    CVE-2018-0492

    Last Modified: 21 Nov 2024

    Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.

    Published: 3 Apr 2018
    7.2
    High

    CVE-2018-0493

    Last Modified: 21 Nov 2024

    remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-4082

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-4083

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar Support" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 3 Apr 2018
    5.5
    Medium

    CVE-2018-4084

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 3 Apr 2018
    8.8
    High

    CVE-2018-4085

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "QuartzCore" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-4087

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Core Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 3 Apr 2018
    5.5
    Medium

    CVE-2018-4090

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 3 Apr 2018
    10
    Critical

    CVE-2018-4091

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Sandbox" component. It allows bypass of a sandbox protection mechanism.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-4095

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Core Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-4097

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-4098

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "IOHIDFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 3 Apr 2018
    8.8
    High

    CVE-2018-4101

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 3 Apr 2018
    6.5
    Medium

    CVE-2018-4102

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

    Published: 3 Apr 2018
    5.5
    Medium

    CVE-2018-4104

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 3 Apr 2018
    9.8
    Critical

    CVE-2018-4105

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "APFS" component. It allows attackers to trigger truncation of an APFS volume password via an unspecified injection.

    Published: 3 Apr 2018
    8.8
    High

    CVE-2018-4106

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands within pasted content.

    Published: 3 Apr 2018
    9.8
    Critical

    CVE-2018-4110

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Web App" component. It allows remote attackers to bypass intended restrictions on cookie persistence.

    Published: 3 Apr 2018
    5.9
    Medium

    CVE-2018-4111

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that references remote resources but lacks a valid S/MIME signature.

    Published: 3 Apr 2018
    5.5
    Medium

    CVE-2018-4112

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.

    Published: 3 Apr 2018
    6.5
    Medium

    CVE-2018-4116

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

    Published: 3 Apr 2018
    8.8
    High

    CVE-2018-4121

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 3 Apr 2018
    8.8
    High

    CVE-2018-4122

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 3 Apr 2018
    2.4
    Low

    CVE-2018-4123

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves alarm and timer handling in the "Clock" component. It allows physically proximate attackers to discover the iTunes e-mail address.

    Published: 3 Apr 2018
    8.8
    High

    CVE-2018-4128

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 3 Apr 2018