CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-0427

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31495866.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0428

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32401526. References: N-CVE-2017-0428.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0429

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32636619. References: N-CVE-2017-0429.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0432

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-28332719.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0434

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33001936.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0435

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31906657. References: QC-CR#1078000.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0436

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32624661. References: QC-CR#1078000.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0437

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402310. References: QC-CR#1092497.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0438

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402604. References: QC-CR#1092497.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0439

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32450647. References: QC-CR#1092059.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0440

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33252788. References: QC-CR#1095770.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0441

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32872662. References: QC-CR#1095009.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0446

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32917445.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0448

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-32721029. References: N-CVE-2017-0448.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0449

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.10. Android ID: A-31707909. References: B-RB#32094.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0450

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it is mitigated by current platform configurations. Product: Android. Versions: N/A. Android ID: A-32917432.

    Published: 8 Feb 2017
    4.7
    Medium

    CVE-2017-0451

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31796345. References: QC-CR#1073129.

    Published: 8 Feb 2017
    9.8
    Critical

    CVE-2016-8418

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Product: Android. Versions: N/A. Android ID: A-32652894. References: QC-CR#1077457.

    Published: 8 Feb 2017
    7
    High

    CVE-2016-8419

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32454494. References: QC-CR#1087209.

    Published: 8 Feb 2017
    7
    High

    CVE-2016-8420

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32451171. References: QC-CR#1087807.

    Published: 8 Feb 2017
    7
    High

    CVE-2016-8476

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32879283. References: QC-CR#1091940.

    Published: 8 Feb 2017
    7
    High

    CVE-2016-8480

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31804432. References: QC-CR#1086186.

    Published: 8 Feb 2017
    7
    High

    CVE-2016-8481

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31906415. References: QC-CR#1078000.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0406

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32915871.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0413

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32161610.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0414

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32807795.

    Published: 8 Feb 2017
    5.3
    Medium

    CVE-2017-0423

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32612586.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0425

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32720785.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0430

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32838767. References: B-RB#107459.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0433

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31913571.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0442

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32871330. References: QC-CR#1092497.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0443

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32877494. References: QC-CR#1092497.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0444

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-32705232.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0445

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32769717.

    Published: 8 Feb 2017
    7
    High

    CVE-2017-0447

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32919560.

    Published: 8 Feb 2017
    9.8
    Critical

    CVE-2017-5929

    Last Modified: 20 Apr 2025

    QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

    Published: 8 Feb 2017
    5
    Medium

    CVE-2017-6436

    Last Modified: 20 Apr 2025

    The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.

    Published: 8 Feb 2017
    5
    Medium

    CVE-2017-6439

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-6500

    Last Modified: 20 Apr 2025

    An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-9374

    Last Modified: 20 Apr 2025

    Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device.

    Published: 8 Feb 2017
    5.9
    Medium

    CVE-2017-12133

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

    Published: 8 Feb 2017
    7.5
    High

    CVE-2017-3135

    Last Modified: 21 Nov 2024

    Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.

    Published: 8 Feb 2017
    9.8
    Critical

    CVE-2017-5953

    Last Modified: 20 Apr 2025

    vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.

    Published: 8 Feb 2017
    6.3
    Medium

    CVE-2016-5372

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

    Published: 7 Feb 2017
    9.8
    Critical

    CVE-2016-5711

    Last Modified: 20 Apr 2025

    NetApp Virtual Storage Console for VMware vSphere before 6.2.1 uses a non-unique certificate, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.

    Published: 7 Feb 2017
    5.9
    Medium

    CVE-2016-6495

    Last Modified: 20 Apr 2025

    NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access.

    Published: 7 Feb 2017
    7.3
    High

    CVE-2016-1502

    Last Modified: 20 Apr 2025

    NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors.

    Published: 7 Feb 2017
    8.1
    High

    CVE-2015-7599

    Last Modified: 20 Apr 2025

    Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.

    Published: 7 Feb 2017
    8.8
    High

    CVE-2015-8322

    Last Modified: 20 Apr 2025

    NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 7 Feb 2017
    7.5
    High

    CVE-2015-8544

    Last Modified: 20 Apr 2025

    NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 7 Feb 2017