Github Exploits

488 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-0518 GITHUB HIGH c
Android Kernel 3.18 - Privilege Escalation
An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32370896. References: QC-CR#1086530.
by ScottyBauer
682 stars
CVSS 7.0
CVE-2017-0516 GITHUB HIGH c
Android Kernel <3.18 - Privilege Escalation
An elevation of privilege vulnerability in the Qualcomm input hardware driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32341680. References: QC-CR#1096301.
by ScottyBauer
682 stars
CVSS 7.0
CVE-2017-0504 GITHUB HIGH c
Android < 7.1.1 - Elevation of Privilege in MediaTek Components
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-30074628. References: M-ALPS02829371.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2017-0451 GITHUB MEDIUM c
Android Kernel 3.10 and 3.18 - Information Disclosure in Qualcomm Sound Driver
An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31796345. References: QC-CR#1073129.
by ScottyBauer
682 stars
CVSS 4.7
CVE-2016-3937 GITHUB HIGH c
Android <2016-10-05 - Privilege Escalation
The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30030994 and MediaTek internal bug ALPS02834874.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-3928 GITHUB HIGH c
Android <2016-10-05 - Privilege Escalation
The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019362 and MediaTek internal bug ALPS02829384.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-3902 GITHUB MEDIUM c
Qualcomm IPA <2016-10-05 - Info Disclosure
drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29953313 and Qualcomm internal bug CR 1044072.
by ScottyBauer
682 stars
CVSS 5.5
CVE-2016-3893 GITHUB MEDIUM c
Qualcomm sound codec - Info Disclosure
The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before 2016-09-05 on Nexus 6P devices does not properly copy firmware data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29512527 and Qualcomm internal bug CR856400.
by ScottyBauer
682 stars
CVSS 5.5
CVE-2016-3868 GITHUB HIGH c
Android <2016-09-05 - Privilege Escalation
The Qualcomm power driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28967028 and Qualcomm internal bug CR1032875.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-3867 GITHUB HIGH c
Qualcomm IPA Driver - Privilege Escalation
The Qualcomm IPA driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28919863 and Qualcomm internal bug CR1037897.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-3815 GITHUB MEDIUM c
NVIDIA Camera Driver - Info Disclosure
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28522274.
by ScottyBauer
682 stars
CVSS 5.5
CVE-2016-3813 GITHUB MEDIUM c
Qualcomm USB driver - Info Disclosure
The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28172322 and Qualcomm internal bug CR1010222.
by ScottyBauer
682 stars
CVSS 5.5
CVE-2016-3797 GITHUB HIGH c
Qualcomm Wi-Fi Driver - Privilege Escalation
The Qualcomm Wi-Fi driver in Android before 2016-07-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085680 and Qualcomm internal bug CR1001450.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-2501 GITHUB HIGH c
Android < 6.0.1 - Privilege Escalation via Qualcomm Camera Driver
The Qualcomm camera driver in Android before 2016-07-05 on Nexus 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 27890772 and Qualcomm internal bug CR1001092.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-2474 GITHUB HIGH c
Qualcomm Wi-Fi driver - Privilege Escalation
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 27424603.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-2469 GITHUB HIGH c
Qualcomm sound driver - Privilege Escalation
The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27531992.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-2465 GITHUB HIGH c
Qualcomm video driver - Privilege Escalation
The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27407865.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-2445 GITHUB HIGH c
Android < 6.0.1 - Privilege Escalation via NVIDIA Media Driver
The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27253079.
by ScottyBauer
682 stars
CVSS 7.0
CVE-2016-2061 GITHUB HIGH c
Linux kernel 3.x - Privilege Escalation
Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overflow and memory corruption) via a crafted application that triggers an msm_isp_axi_create_stream call.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2016-0822 GITHUB HIGH c
Android 6.0.1 - Privilege Escalation
The MediaTek connectivity kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application that leverages conn_launcher access, aka internal bug 25873324.
by ScottyBauer
682 stars
CVSS 7.0
CVE-2015-0572 GITHUB HIGH c
Linux Kernel 3.0-3.19.8 - Race Condition in ADSPRPC Driver via COMPAT_FASTRPC_IOCTL_INVOKE_FD
Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service (zero-value write) or possibly have unspecified other impact via a COMPAT_FASTRPC_IOCTL_INVOKE_FD ioctl call.
by ScottyBauer
682 stars
CVSS 7.0
CVE-2018-5333 GITHUB MEDIUM c
Linux kernel <4.14.13 - Memory Corruption
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
by TamiiLambrado
3 stars
CVSS 5.5
CVE-2018-5332 GITHUB HIGH c
Linux kernel <3.2 - Memory Corruption
In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).
by TamiiLambrado
3 stars
CVSS 7.8
CVE-2017-8824 GITHUB HIGH c
Linux kernel through 4.14.3 - Use-After-Free in DCCP Disconnect Handler
The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.
by TamiiLambrado
3 stars
CVSS 7.8
CVE-2017-17712 GITHUB HIGH c
Linux Kernel 3.19-4.1.52 - Local Privilege Escalation via Race Condition in raw_sendmsg
The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows a local user to execute code and gain privileges.
by TamiiLambrado
3 stars
CVSS 7.0