CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102444 | CVE-2017-5624 | Candidate | An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by issuing the "fastboot oem disable_dm_verity" command. Having dm-verity disabled, the kernel will not verify the system partition (and any other dm-verity protected partition), which may allow for persistent code execution and privilege escalation. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102445 | CVE-2017-5625 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102446 | CVE-2017-5626 | Candidate | OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the bootloader, disregarding the "OEM Unlocking" checkbox, without user confirmation and without a factory reset. This allows for persistent code execution with high privileges (kernel/root) with complete access to user data. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102447 | CVE-2017-5627 | Candidate | An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b8a1a9326ce08. The jsR_setproperty function in jsrun.c lacks a check for a negative array length. This leads to an integer overflow in the js_pushstring function in jsrun.c when parsing a specially crafted JS file. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102448 | CVE-2017-5628 | Candidate | An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow when parsing a specially crafted JS file. | Assigned (20170129) | None (candidate not yet proposed) | View |
Page 1076 of 20943, showing 5 records out of 104715 total, starting on record 5376, ending on 5380