New issue
Advanced search Search tips
ListGrid
Loading...
  ID Type  Status  Priority  Milestone  Owner  Summary + Labels ...
  162 ---- Fixed ---- ---- markbrand@google.com Chrome heap underflow caused by integer issue in ICU regex engine CCProjectZeroMembers  
  199 ---- Fixed ---- ---- cevans@google.com Flash PCRE regex compilation logic issue CCProjectZeroMembers  
  208 ---- Fixed ---- ---- cevans@google.com Flash PCRE pcre_compile character class/ims options heap overflow CCProjectZeroMembers  
  216 ---- Fixed ---- ---- cevans@google.com Flash PCRE regex compilation recursion offset arbitrary bytecode execution CCProjectZeroMembers  
  224 ---- Fixed ---- ---- cevans@google.com Flash PCRE regex compilation zero-length assertion arbitrary bytecode execution CCProjectZeroMembers  
  225 ---- Fixed ---- ---- cevans@google.com Flash PCRE regex compilation extended unicode comment arbitrary bytecode execution CCProjectZeroMembers  
  231 ---- Fixed ---- ---- cevans@google.com Mongoose Web Server - Multiple integer issues CCProjectZeroMembers  
  364 ---- Fixed ---- ---- cevans@google.com Chrome heap overflow in CertificateResourceHandler CCProjectZeroMembers  
  407 ---- Fixed ---- ---- cevans@google.com Chrome heap overflow in Linux HID device handler CCProjectZeroMembers  
  487 ---- Fixed ---- ---- ianbeer@google.com OS X coreaudiod calls uninitialized function pointer CCProjectZeroMembers  
  489 ---- Fixed ---- ---- hawkes@google.com Samsung WifiHs20UtilityService path traversal CCProjectZeroMembers  
  513 ---- Fixed ---- ---- markbrand@google.com Chrome - Integer overflow in open-vcdiff results in OOB read in browser process CCProjectZeroMembers  
  540 ---- Invalid ---- ---- markbrand@google.com Linux: kernel read-write in __ARM_NR_cmpxchg CCProjectZeroMembers  
  678 ---- Fixed ---- ---- markbrand@google.com Android One mt_wifi IOCTL_GET_STRUCT EOP CCProjectZeroMembers  
  780 ---- Fixed ---- ---- markbrand@google.com Chrome - GPU process MailboxManagerImpl double-read CCProjectZeroMembers  
  787 ---- Fixed ---- ---- markbrand@google.com Chrome - GPU process BufferManager double-reads CCProjectZeroMembers  
  795 ---- Fixed ---- ---- markbrand@google.com Samsung Android: JACK ASLR bypass CCProjectZeroMembers  
  796 ---- Fixed ---- ---- markbrand@google.com Samsung Android: JACK privilege elevation CCProjectZeroMembers  
  798 ---- Fixed ---- ---- markbrand@google.com Android: Stack-buffer-overflow in /system/bin/sdcard CCProjectZeroMembers  
  812 ---- Fixed ---- ---- markbrand@google.com Reference count leak in apparmor securityfs aa_fs_seq_hash_show CCProjectZeroMembers  
  840 ---- Fixed ---- ---- markbrand@google.com Android - libutils UTF16 to UTF8 conversion heap-buffer-overflow CCProjectZeroMembers  
  889 ---- Fixed ---- ---- markbrand@google.com Android: Binder generic ASLR leak CCProjectZeroMembers  
  932 ---- Fixed ---- ---- markbrand@google.com Android - IOMXNodeInstance::enableNativeBuffers unchecked index CCProjectZeroMembers  
  958 ---- Fixed ---- ---- markbrand@google.com Android - Stack overflow in WifiNative::setHotlist CCProjectZeroMembers  
  986 ---- Fixed ---- ---- markbrand@google.com LG: Multiple race conditions in lgdrmserver binder service. CCProjectZeroMembers  
  987 ---- Fixed ---- ---- markbrand@google.com LG: Directory traversal in lghashstorageserver CCProjectZeroMembers  
  990 ---- Fixed ---- ---- markbrand@google.com LG: touchscreen driver write_log kernel read/write CCProjectZeroMembers  
  991 ---- Fixed ---- ---- markbrand@google.com LG: Felica driver dangerous set_fs usage CCProjectZeroMembers  
  1102 ---- Fixed ---- ---- markbrand@google.com LG: Bad alloca calls in liblg_parser_mkv.so CCProjectZeroMembers  
  1117 ---- Fixed ---- ---- markbrand@google.com LG: Failure to initialise pointers in mkvparser::Tracks constructor CCProjectZeroMembers  
  1124 ---- Fixed ---- ---- markbrand@google.com LG: Heap buffer overflows in mkvparser::Block::Block CCProjectZeroMembers  
  1158 ---- Fixed ---- ---- markbrand@google.com LG: Use of uninitialised pointer in OGMParser::VerifyVorbisHeader CCProjectZeroMembers  
  1206 ---- Fixed ---- ---- markbrand@google.com LG: Missing bounds-checking in AVI stream parsing CCProjectZeroMembers  
  1221 ---- Fixed ---- ---- markbrand@google.com LG: Out-of-bounds heap read in CAVIFileParser::Destroy resulting in invalid free CCProjectZeroMembers  
  1222 ---- Fixed ---- ---- markbrand@google.com LG: Missing bounds checking in ASFParser::ParseHeaderExtensionObjects CCProjectZeroMembers  
  1226 ---- Fixed ---- ---- markbrand@google.com LG: Stack overflows in ASFParser::SetMetaData CCProjectZeroMembers