| <html devsite><head> |
| <title>Android 安全公告 - 2018 年 4 月</title> |
| <meta name="project_path" value="/_project.yaml"/> |
| <meta name="book_path" value="/_book.yaml"/> |
| </head> |
| <body> |
| <!-- |
| Copyright 2018 The Android Open Source Project |
| |
| Licensed under the Apache License, Version 2.0 (the "License"); |
| you may not use this file except in compliance with the License. |
| You may obtain a copy of the License at |
| |
| //www.apache.org/licenses/LICENSE-2.0 |
| |
| Unless required by applicable law or agreed to in writing, software |
| distributed under the License is distributed on an "AS IS" BASIS, |
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| See the License for the specific language governing permissions and |
| limitations under the License. |
| --> |
| <p><em>发布时间:2018 年 4 月 2 日 | 更新时间:2018 年 4 月 4 日</em></p> |
| |
| <p> |
| 本 Android 安全公告详细介绍了会影响 Android 设备的安全漏洞。安全补丁程序级别为 2018-04-05 或更新的 Android 系统都已解决本公告中所述的所有问题。要了解如何查看设备的安全补丁程序级别,请参阅<a href="https://support.google.com/pixelphone/answer/4457705">查看并更新 Android 版本</a>。 |
| </p> |
| <p> |
| Android 合作伙伴在本公告发布前至少一个月就已收到关于所有问题的通知。我们已将针对这些问题的源代码补丁程序发布到 Android 开源项目 (AOSP) 代码库中,并在本公告中提供了相应链接。本公告中还提供了指向 AOSP 之外的补丁程序的链接。 |
| </p> |
| <p> |
| 这些问题中危险性最高的是媒体框架中的一个严重程度为“严重”的安全漏洞,该漏洞可让远程攻击者利用蓄意创建的文件通过特权进程执行任意代码。<a href="/security/overview/updates-resources.html#severity">严重程度评估</a>的依据是漏洞被利用后可能会对受影响的设备造成的影响(假设相关平台和服务缓解措施被成功规避或出于开发目的而被停用)。 |
| </p> |
| <p> |
| 尚未有人向我们举报过有用户主动利用或滥用这些新报告的问题。请参阅 <a href="#mitigations">Android 和 Google Play 保护机制提供的缓解措施</a>部分,详细了解有助于提高 Android 平台安全性的 <a href="/security/enhancements/index.html">Android 安全平台防护功能</a>和 Google Play 保护机制。 |
| </p> |
| <p class="note"> |
| <strong>注意</strong>:如需了解适用于 Google 设备的最新无线下载更新 (OTA) 和固件映像,请参阅 <a href="/security/bulletin/pixel/2018-04-01.html">2018 年 4 月的 Pixel/Nexus 安全公告</a>。 |
| </p> |
| |
| <h2 id="announcements">通告</h2> |
| <p>我们衷心感谢 Qualcomm 为改进移动设备的安全性做出的贡献。2018-04-05 SPL 包含了 Qualcomm 2014-2016 年合作伙伴关注公告中已解决的安全问题的累积清单,反映了他们对持续努力和改进的承诺。</p> |
| |
| <h2 id="mitigations">Android 和 Google 服务缓解措施</h2> |
| <p> |
| 这一部分总结了 <a href="/security/enhancements/index.html">Android 安全平台</a>和服务防护功能(如 <a href="https://www.android.com/play-protect">Google Play 保护机制</a>)提供的缓解措施。这些功能有助于降低 Android 上的安全漏洞被成功利用的可能性。 |
| </p> |
| <ul> |
| <li>较高版本的 Android 平台中提供的增强功能让攻击者更加难以利用 Android 上存在的许多问题。我们建议所有用户都尽可能更新到最新版 Android。</li> |
| <li>Android 安全团队会积极利用 <a href="https://www.android.com/play-protect">Google Play 保护机制</a>监控滥用行为,并会在发现<a href="/security/reports/Google_Android_Security_PHA_classifications.pdf">可能有害的应用</a>时向用户发出警告。在安装有 <a href="http://www.android.com/gms">Google 移动服务</a>的设备上,Google Play 保护机制会默认处于启用状态,对于从 Google Play 以外的来源安装应用的用户来说,该功能尤为重要。</li> |
| </ul> |
| <h2 id="2018-04-01-details">2018-04-01 安全补丁程序级别 - 漏洞详情</h2> |
| <p> |
| 我们在下面提供了 2018-04-01 补丁程序级别涵盖的每个安全漏洞的详细信息。漏洞列在所影响的组件下,内容包括问题描述和一个表,该表中包含 CVE、相关参考内容、<a href="#type">漏洞类型</a>、<a href="/security/overview/updates-resources.html#severity">严重程度</a>和已更新的 AOSP 版本(如果适用)。如果有解决相应问题的公开更改记录(例如 AOSP 代码更改列表),我们会将 Bug ID 链接到该记录。如果某个 Bug 有多条相关的代码更改记录,我们还会通过 Bug ID 后面的数字链接到更多参考内容。 |
| </p> |
| |
| <h3 id="android-runtime">Android 运行时</h3> |
| <p>这一部分中最严重的漏洞可让远程攻击者绕过用户互动要求来获得额外的权限。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>已更新的 AOSP 版本</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13274</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/0b57631939f5824afef06517df723d2e766e0159">A-71360761</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="framework">框架</h3> |
| <p>这一部分中最严重的漏洞可让本地恶意应用绕过将应用数据与其他应用分隔开来的操作系统防护功能。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>已更新的 AOSP 版本</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13275</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/minikin/+/3056f04d293bd16e56cc72e10edd060b8c1ca0f5">A-70808908</a></td> |
| <td>ID</td> |
| <td>高</td> |
| <td>8.0、8.1</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="media-framework">媒体框架</h3> |
| <p>这一部分中最严重的漏洞可让远程攻击者利用蓄意创建的文件通过特权进程执行任意代码。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>已更新的 AOSP 版本</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13276</td> |
| <td><a href="https://android.googlesource.com/platform/external/aac/+/1b9cbed05b4fd376677d67b6442aa30256834ed4">A-70637599</a></td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13277</td> |
| <td><a href="https://android.googlesource.com/platform/external/libhevc/+/b7d4d588e8fcbe254f7a3d9a247af4b91ccc7285">A-72165027</a></td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13278</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/av/+/8a54af87b632c03ff2ae15a4a088801bb39fdae7">A-70546581</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13279</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/av/+/d32af5db10f018219e0379f333c7f0452a4f7a31">A-68399439</a></td> |
| <td>DoS</td> |
| <td>高</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13280</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/ex/+/ebd849ed8aa77c0e1dad7a08df4a55845a067b76">A-71361451</a></td> |
| <td>DoS</td> |
| <td>高</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="system">系统</h3> |
| <p>这一部分中最严重的漏洞可让远程攻击者利用蓄意创建的文件通过特权进程执行任意代码。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>已更新的 AOSP 版本</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13281</td> |
| <td><a href="https://android.googlesource.com/platform/system/bt/+/6f3ddf3f5cf2b3eb52fb0adabd814a45cff07221">A-71603262</a></td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13282</td> |
| <td><a href="https://android.googlesource.com/platform/system/bt/+/6ecbbc093f4383e90cbbf681cd55da1303a8ef94">A-71603315</a></td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13283</td> |
| <td><a href="https://android.googlesource.com/platform/system/bt/+/e4ec79be45304f819c88c8dbf826d58b68f6c8f8">A-71603410</a></td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13267</td> |
| <td><a href="https://android.googlesource.com/platform/system/bt/+/57dc5964428697a104988f0aa0d1fd1d88fec939">A-69479009</a></td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13284</td> |
| <td><a href="https://android.googlesource.com/platform/system/bt/+/7f8bfcc35285ca6e93a4436699bc95c13b920caf">A-70808273</a></td> |
| <td>EoP</td> |
| <td>严重</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13285</td> |
| <td><a href="https://android.googlesource.com/platform/external/svox/+/cee78199bbfae81f54a40671db47096f5f32cdad">A-69177126</a></td> |
| <td>RCE</td> |
| <td>高</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13286</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/47ebfaa2196aaf4fbeeec34f1a1c5be415cf041b">A-69683251</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13287</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/09ba8fdffd9c8d74fdc6bfb51bcebc27fc43884a">A-71714464</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13288</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/b796cd32a45bcc0763c50cc1a0cc8236153dcea3">A-69634768</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13289</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/5a3d2708cd2289a4882927c0e2cb0d3c21a99c02">A-70398564</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13290</td> |
| <td><a href="https://android.googlesource.com/platform/system/bt/+/72b1cebaa9cc7ace841d887f0d4a4bf6daccde6e">A-69384124</a></td> |
| <td>ID</td> |
| <td>高</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13291</td> |
| <td><a href="https://android.googlesource.com/platform/system/bt/+/1696f97011f5f30f1a630f3b24442ca64232b1f5">A-71603553</a></td> |
| <td>DoS</td> |
| <td>高</td> |
| <td>7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| </tbody></table> |
| |
| <h2 id="2018-04-05-details">2018-04-05 安全补丁程序级别 - 漏洞详情</h2> |
| <p>我们在下面提供了 2018-04-05 补丁程序级别涵盖的每个安全漏洞的详细信息。漏洞列在所影响的组件下,内容包括 CVE、相关参考内容、<a href="#type">漏洞类型</a>、<a href="/security/overview/updates-resources.html#severity">严重程度</a>、组件(如果适用)和已更新的 AOSP 版本(如果适用)等详细信息。如果有解决相应问题的公开更改记录(例如 AOSP 代码更改列表),我们会将 Bug ID 链接到该记录。</p> |
| |
| <p>如果某个 Bug 有多条相关的代码更改记录,我们还会通过 Bug ID 后面的数字链接到更多参考内容。</p> |
| |
| <h3 id="broadcom-components">Broadcom 组件</h3> |
| <p>这一部分中最严重的漏洞可让邻近区域内的攻击者利用蓄意创建的文件通过特权进程执行任意代码。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>组件</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13292</td> |
| <td>A-70722061<a href="#asterisk">*</a><br />B-V2018010201</td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>Bcmdhd 驱动程序</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="kernel-components">内核组件</h3> |
| <p>这一部分中最严重的漏洞可让本地恶意应用通过特权进程执行任意代码。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>组件</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13293</td> |
| <td>A-62679701<a href="#asterisk">*</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>NFC 驱动程序</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-16534</td> |
| <td>A-69052594<br /> |
| <a href="https://github.com/torvalds/linux/commit/2e1c42391ff2556387b3cb6308b24f6f65619feb">上游内核</a></td> |
| <td>ID</td> |
| <td>高</td> |
| <td>USB</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="qualcomm-components">Qualcomm 组件</h3> |
| <p>这一部分中最严重的漏洞可让邻近区域内的攻击者利用蓄意创建的文件通过特权进程执行任意代码。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="21%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="37%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>组件</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-15822</td> |
| <td>A-71501534<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=dba4c106922d637ff5965b023b451f6273348eb6">QC-CR#2123807</a></td> |
| <td>RCE</td> |
| <td>严重</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-17770</td> |
| <td>A-70237684<br /> |
| <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=284f963af0accf7f921ec10e23acafd71c3a724b">QC-CR#2103199</a> |
| [<a href="https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=3b0c1463e4a6b37d4413a4ba02f1727eeb8693be">2</a>]</td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>Binder</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3566</td> |
| <td>A-72957177<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=11868230d4fe79f76eae30c742b4c68c2899caea">QC-CR#2143847</a></td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3563</td> |
| <td>A-72956842<br /> |
| <a href="https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=c643a15d73b3fb6329b002662e72dfa96acfdb8a">QC-CR#2143207</a> |
| [<a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=0b8320cd49255177f0c0c8589708e983116ac420">2</a>] |
| [<a href="https://source.codeaurora.org/quic/la/platform/vendor/opensource/audio-kernel/commit/?id=d5231fa166521a32621c32fb749b80fc37c13c6a">3</a>]</td> |
| <td>EoP</td> |
| <td>高</td> |
| <td>音频驱动程序</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13077</td> |
| <td>A-72957017<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=776f17c87599fae3202e69bb5718ac9062f14695">QC-CR#2129237</a></td> |
| <td>ID</td> |
| <td>高</td> |
| <td>WLAN</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="qualcomm-closed-source-components">Qualcomm 闭源组件</h3> |
| <p>以下漏洞会影响 Qualcomm 组件,相应的 Qualcomm AMSS 安全公告或安全提醒中对这些漏洞进行了详细说明。这些漏洞的严重程度评估是由 Qualcomm 直接提供的。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>组件</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-18071</td> |
| <td>A-68326813<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>严重</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-8274</td> |
| <td>A-68141335<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>严重</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18146</td> |
| <td>A-70221449<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>严重</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18128</td> |
| <td>A-70221448<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>严重</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3592</td> |
| <td>A-71501105<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>严重</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3591</td> |
| <td>A-71501103<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>严重</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18074</td> |
| <td>A-68326816<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18073</td> |
| <td>A-68326820<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18125</td> |
| <td>A-68326821<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-8275</td> |
| <td>A-68141336<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-11011</td> |
| <td>A-68326823<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18137</td> |
| <td>A-67712318<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18134</td> |
| <td>A-67712320<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18136</td> |
| <td>A-68989810<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18140</td> |
| <td>A-68989811<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18135</td> |
| <td>A-68989813<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18142</td> |
| <td>A-68989814<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18138</td> |
| <td>A-68989815<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18139</td> |
| <td>A-68989819<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18129</td> |
| <td>A-68989822<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18132</td> |
| <td>A-68989825<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18133</td> |
| <td>A-68989826<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18072</td> |
| <td>A-68989828<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18126</td> |
| <td>A-68989829<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18144</td> |
| <td>A-70221450<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18145</td> |
| <td>A-70221453<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18147</td> |
| <td>A-70221456<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18130</td> |
| <td>A-70221460<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18143</td> |
| <td>A-70221461<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2017-18127</td> |
| <td>A-70221462<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件 |
| </td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3590</td> |
| <td>A-71501106<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3593</td> |
| <td>A-71501107<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3589</td> |
| <td>A-71501108<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3594</td> |
| <td>A-71501112<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="qualcomm-closed-source-components-2014-2016-cumulative-update">Qualcomm 闭源组件 2014-2016 年积累更新</h3> |
| <p>以下漏洞会影响 Qualcomm 组件,并已通过 Qualcomm AMSS 安全公告或安全提醒在 2014 年至 2016 年期间由 Qualcomm 与其合作伙伴共享。此 Android 安全公告中也包含这些漏洞,旨在将其修复程序与 Android 安全补丁程序级别建立关联(许多 Android 设备可能已在之前的更新中解决了这些问题)。这些漏洞的严重程度评估是由 Qualcomm 直接提供的。</p> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>参考内容</th> |
| <th>类型</th> |
| <th>严重程度</th> |
| <th>组件</th> |
| </tr> |
| <tr> |
| <td>CVE-2014-9996</td> |
| <td>A-37535090<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>严重</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9971</td> |
| <td>A-37546253<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9972</td> |
| <td>A-37546853<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10063</td> |
| <td>A-37534948<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10057</td> |
| <td>A-62261099<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10059</td> |
| <td>A-62260706<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10053</td> |
| <td>A-37544066<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10054</td> |
| <td>A-62261100<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10052</td> |
| <td>A-62258372<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10050</td> |
| <td>A-37546901<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10055</td> |
| <td>A-37545605<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10051</td> |
| <td>A-37546302<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10048</td> |
| <td>A-62258088<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10062</td> |
| <td>A-62258373<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10058</td> |
| <td>A-62260741<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10047</td> |
| <td>A-37538492<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10045</td> |
| <td>A-62258536<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10056</td> |
| <td>A-62261338<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9976</td> |
| <td>A-37534895<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10043</td> |
| <td>A-62259947<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10044</td> |
| <td>A-62260777<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10046</td> |
| <td>A-62261408<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9981</td> |
| <td>A-37534949<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9993</td> |
| <td>A-37540928<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9986</td> |
| <td>A-37534645<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9994</td> |
| <td>A-37538493<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9995</td> |
| <td>A-37546303<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9997</td> |
| <td>A-37546854<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9988</td> |
| <td>A-62258089<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9990</td> |
| <td>A-62261216<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9987</td> |
| <td>A-62261293<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9989</td> |
| <td>A-62261380<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9991</td> |
| <td>A-62261409<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-10039</td> |
| <td>A-62261608<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9985</td> |
| <td>A-62261609<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9204</td> |
| <td>A-37540929<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-0574</td> |
| <td>A-37546304<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9205</td> |
| <td>A-37534696<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9221</td> |
| <td>A-37534796<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9212</td> |
| <td>A-37535795<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9210</td> |
| <td>A-62258538<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9211</td> |
| <td>A-62261217<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9207</td> |
| <td>A-62261410<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9202</td> |
| <td>A-37540473<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9213</td> |
| <td>A-37547700<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9209</td> |
| <td>A-38193247<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9203</td> |
| <td>A-62261218<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9206</td> |
| <td>A-62261294<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9215</td> |
| <td>A-62251854<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9216</td> |
| <td>A-62260780<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9169</td> |
| <td>A-37535098<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9173</td> |
| <td>A-37536244<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9179</td> |
| <td>A-37542567<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9177</td> |
| <td>A-37544075<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9187</td> |
| <td>A-37544109<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9162</td> |
| <td>A-37544110<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9172</td> |
| <td>A-37545607<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9181</td> |
| <td>A-37546754<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9219</td> |
| <td>A-37546859<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9183</td> |
| <td>A-37546860<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9182</td> |
| <td>A-37546904<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9185</td> |
| <td>A-37546952<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9184</td> |
| <td>A-37546953<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9170</td> |
| <td>A-37546954<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9175</td> |
| <td>A-37547404<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9171</td> |
| <td>A-37547405<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9192</td> |
| <td>A-37547750<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9208</td> |
| <td>A-62258540<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9224</td> |
| <td>A-62259949<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9201</td> |
| <td>A-62260711<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9200</td> |
| <td>A-62260779<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9198</td> |
| <td>A-62261219<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9196</td> |
| <td>A-62261339<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9199</td> |
| <td>A-62261411<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9174</td> |
| <td>A-62258090<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9178</td> |
| <td>A-62258541<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9180</td> |
| <td>A-62260712<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9176</td> |
| <td>A-62260713<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9189</td> |
| <td>A-62260820<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9188</td> |
| <td>A-62260821<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-0576</td> |
| <td>A-37543715<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9156</td> |
| <td>A-62260743<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9195</td> |
| <td>A-62251855<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9197</td> |
| <td>A-62260742<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9218</td> |
| <td>A-62260781<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9217</td> |
| <td>A-62261295<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9166</td> |
| <td>A-62251856<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9164</td> |
| <td>A-62258542<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9190</td> |
| <td>A-62259744<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9159</td> |
| <td>A-62259745<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9167</td> |
| <td>A-62259950<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9191</td> |
| <td>A-62260394<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9161</td> |
| <td>A-62260462<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9163</td> |
| <td>A-62260822<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9158</td> |
| <td>A-62261381<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9152</td> |
| <td>A-37546305<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9144</td> |
| <td>A-37540474<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9165</td> |
| <td>A-37539224<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9223</td> |
| <td>A-37543718<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9222</td> |
| <td>A-62258374<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9193</td> |
| <td>A-62259951<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9194</td> |
| <td>A-62261296<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9153</td> |
| <td>A-62260395<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9151</td> |
| <td>A-62260396<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9148</td> |
| <td>A-62260463<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9149</td> |
| <td>A-62260744<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9146</td> |
| <td>A-62260745<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9186</td> |
| <td>A-62261340<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9150</td> |
| <td>A-62261341<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9147</td> |
| <td>A-62261488<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-8593</td> |
| <td>A-37535091<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9160</td> |
| <td>A-37546254<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-8594</td> |
| <td>A-37546855<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9145</td> |
| <td>A-37535099<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9143</td> |
| <td>A-62260900<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9157</td> |
| <td>A-62260934<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9141</td> |
| <td>A-62261297<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9140</td> |
| <td>A-62259746<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9135</td> |
| <td>A-37546950<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9138</td> |
| <td>A-62259952<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9136</td> |
| <td>A-62260823<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9137</td> |
| <td>A-62260975<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9131</td> |
| <td>A-37542272<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9139</td> |
| <td>A-62251857<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9130</td> |
| <td>A-62252820<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9129</td> |
| <td>A-62260397<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9133</td> |
| <td>A-62260464<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9127</td> |
| <td>A-62260824<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9132</td> |
| <td>A-62260976<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9134</td> |
| <td>A-62261382<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9128</td> |
| <td>A-62261610<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9065</td> |
| <td>A-37538494<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9064</td> |
| <td>A-37546801<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9063</td> |
| <td>A-37546802<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9126</td> |
| <td>A-62258375<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9124</td> |
| <td>A-62252821<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9142</td> |
| <td>A-62260901<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9066</td> |
| <td>A-37540467<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2014-9998</td> |
| <td>A-62260398<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9220</td> |
| <td>A-62261299<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9122</td> |
| <td>A-62261611<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9123</td> |
| <td>A-62259953<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9118</td> |
| <td>A-62261220<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9120</td> |
| <td>A-62261298<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9119</td> |
| <td>A-62261489<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9116</td> |
| <td>A-37540934<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9115</td> |
| <td>A-37544076<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9113</td> |
| <td>A-37544077<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9112</td> |
| <td>A-62258091<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9114</td> |
| <td>A-62259954<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9111</td> |
| <td>A-62260465<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9108</td> |
| <td>A-62260714<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9109</td> |
| <td>A-62260977<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2015-9110</td> |
| <td>A-62261383<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10492</td> |
| <td>A-62261300<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10482</td> |
| <td>A-62260978<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10483</td> |
| <td>A-62258092<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10489</td> |
| <td>A-62258093<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10487</td> |
| <td>A-62259955<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10477</td> |
| <td>A-62260399<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10485</td> |
| <td>A-62260902<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10478</td> |
| <td>A-62260979<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10476</td> |
| <td>A-62260980<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10475</td> |
| <td>A-62260981<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10474</td> |
| <td>A-62260982<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10494</td> |
| <td>A-62261102<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10484</td> |
| <td>A-62261342<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10491</td> |
| <td>A-62261490<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10486</td> |
| <td>A-62267788<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10472</td> |
| <td>A-62259956<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10490</td> |
| <td>A-62260468<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10480</td> |
| <td>A-62261301<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10467</td> |
| <td>A-37526814<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10495</td> |
| <td>A-62261103<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10481</td> |
| <td>A-62260401<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10479</td> |
| <td>A-62261412<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10384</td> |
| <td>A-37536238<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10385</td> |
| <td>A-37544067<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10452</td> |
| <td>A-37523164<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10423</td> |
| <td>A-37534896<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10424</td> |
| <td>A-37540034<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10449</td> |
| <td>A-37546861<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10454</td> |
| <td>A-37544078<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10450</td> |
| <td>A-62260825<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10451</td> |
| <td>A-62267789<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10386</td> |
| <td>A-37534646<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10469</td> |
| <td>A-37542273<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10440</td> |
| <td>A-37535092<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10499</td> |
| <td>A-62259957<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10446</td> |
| <td>A-37547406<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10473</td> |
| <td>A-62260746<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10466</td> |
| <td>A-62260783<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10457</td> |
| <td>A-62260826<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10442</td> |
| <td>A-62267790<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10433</td> |
| <td>A-37540468<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10430</td> |
| <td>A-37540930<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10445</td> |
| <td>A-37545608<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10426</td> |
| <td>A-62252822<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10435</td> |
| <td>A-62260402<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10425</td> |
| <td>A-62260983<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10438</td> |
| <td>A-62261302<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10436</td> |
| <td>A-62261494<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10439</td> |
| <td>A-62263656<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10431</td> |
| <td>A-37540931<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10434</td> |
| <td>A-37540932<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10432</td> |
| <td>A-37546902<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10462</td> |
| <td>A-37539225<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10443</td> |
| <td>A-37540475<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10427</td> |
| <td>A-62261495<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10387</td> |
| <td>A-32583751<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10390</td> |
| <td>A-37536239<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10498</td> |
| <td>A-32582870<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10419</td> |
| <td>A-32577129<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10420</td> |
| <td>A-32579916<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10429</td> |
| <td>A-32579411<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10493</td> |
| <td>A-32574787<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10447</td> |
| <td>A-37542968<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10444</td> |
| <td>A-37544163<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-5348</td> |
| <td>A-37546905<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10421</td> |
| <td>A-32579095<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10455</td> |
| <td>A-32580964<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10441</td> |
| <td>A-32582927<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10418</td> |
| <td>A-37547407<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10417</td> |
| <td>A-32576287<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10464</td> |
| <td>A-32580243<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10458</td> |
| <td>A-32583424<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10471</td> |
| <td>A-37539226<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10416</td> |
| <td>A-62259747<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10411</td> |
| <td>A-62260404<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10496</td> |
| <td>A-62260469<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10410</td> |
| <td>A-62260936<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10414</td> |
| <td>A-62260937<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10461</td> |
| <td>A-62263657<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10460</td> |
| <td>A-62271227<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10392</td> |
| <td>A-37544068<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10409</td> |
| <td>A-37544164<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10459</td> |
| <td>A-62260716<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10407</td> |
| <td>A-62261222<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10406</td> |
| <td>A-62267791<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10497</td> |
| <td>A-62271228<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10501</td> |
| <td>A-62261303<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>高</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10381</td> |
| <td>A-37539788<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10380</td> |
| <td>A-37541976<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10412</td> |
| <td>A-37536245<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10415</td> |
| <td>A-62260403<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10422</td> |
| <td>A-37542966<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10456</td> |
| <td>A-62261413<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10428</td> |
| <td>A-37534697<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10448</td> |
| <td>A-62261414<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| <tr> |
| <td>CVE-2016-10437</td> |
| <td>A-62260715<a href="#asterisk">*</a></td> |
| <td>N/A</td> |
| <td>中</td> |
| <td>闭源组件</td> |
| </tr> |
| </tbody></table> |
| |
| <h2 id="common-questions-and-answers">常见问题和解答</h2> |
| <p> |
| 这一部分解答了用户在阅读本公告后可能会提出的常见问题。</p> |
| <p><strong>1. 如何确定我的设备是否已通过更新解决这些问题? |
| </strong></p> |
| <p>要了解如何查看设备的安全补丁程序级别,请参阅<a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices">查看并更新 Android 版本</a>。</p> |
| <ul> |
| <li>如果安全补丁程序级别是 2018-04-01 或更新,则意味着已解决 2018-04-01 安全补丁程序级别涵盖的所有问题。</li> |
| <li>如果安全补丁程序级别是 2018-04-05 或更新,则意味着已解决 2018-04-05 以及之前的所有安全补丁程序级别涵盖的所有问题。</li> |
| </ul> |
| <p> |
| 预装这些更新的设备制造商应将补丁程序字符串级别设为: |
| </p> |
| <ul> |
| <li>[ro.build.version.security_patch]:[2018-04-01]</li> |
| <li>[ro.build.version.security_patch]:[2018-04-05]</li> |
| </ul> |
| <p> |
| <strong>2. 为何本公告有 2 个安全补丁程序级别?</strong> |
| </p> |
| <p> |
| 本公告之所以有 2 个安全补丁程序级别,是为了让 Android 合作伙伴能够灵活地、更快速地修复在各种 Android 设备上类似的一系列漏洞。我们建议 Android 合作伙伴修复本公告中的所有问题并使用最新的安全补丁程序级别。 |
| </p> |
| <ul> |
| <li>如果设备使用的是 2018-04-01 这一安全补丁程序级别,则必须包含该安全补丁程序级别涵盖的所有问题以及之前的安全公告中报告的所有问题的修复程序。</li> |
| <li>如果设备使用的是 2018-04-05 或更新的安全补丁程序级别,则必须包含本安全公告(以及之前的安全公告)中的所有适用补丁程序。</li> |
| </ul> |
| <p> |
| 我们建议合作伙伴将要解决的全部问题的修复程序打包到一个更新中。 |
| </p> |
| <p id="type"> |
| <strong>3.“类型”列中的条目表示什么意思?<em></em></strong> |
| </p> |
| <p> |
| 在漏洞详情表内,“类型”列中的条目是安全漏洞的分类。<em></em> |
| </p> |
| <table> |
| <colgroup><col width="25%" /> |
| <col width="75%" /> |
| </colgroup><tbody><tr> |
| <th>缩写词</th> |
| <th>定义</th> |
| </tr> |
| <tr> |
| <td>RCE</td> |
| <td>远程代码执行</td> |
| </tr> |
| <tr> |
| <td>EoP</td> |
| <td>提权</td> |
| </tr> |
| <tr> |
| <td>ID</td> |
| <td>信息披露</td> |
| </tr> |
| <tr> |
| <td>DoS</td> |
| <td>拒绝服务</td> |
| </tr> |
| <tr> |
| <td>N/A</td> |
| <td>没有分类</td> |
| </tr> |
| </tbody></table> |
| <p> |
| <strong>4.“参考内容”列中的条目表示什么意思?<em></em></strong> |
| </p> |
| <p> |
| 在漏洞详情表内,“参考内容”列中的条目可能包含用于标识参考值所属组织的前缀。<em></em> |
| </p> |
| <table> |
| <colgroup><col width="25%" /> |
| <col width="75%" /> |
| </colgroup><tbody><tr> |
| <th>前缀</th> |
| <th>参考内容</th> |
| </tr> |
| <tr> |
| <td>A-</td> |
| <td>Android Bug ID</td> |
| </tr> |
| <tr> |
| <td>QC-</td> |
| <td>Qualcomm 参考编号</td> |
| </tr> |
| <tr> |
| <td>M-</td> |
| <td>MediaTek 参考编号</td> |
| </tr> |
| <tr> |
| <td>N-</td> |
| <td>NVIDIA 参考编号</td> |
| </tr> |
| <tr> |
| <td>B-</td> |
| <td>Broadcom 参考编号</td> |
| </tr> |
| </tbody></table> |
| <p id="asterisk"> |
| <strong>5. 在“参考内容”列中,Android Bug ID 旁边的 * 表示什么意思?<em></em></strong> |
| </p> |
| <p> |
| 如果问题尚未公开发布,则在“参考内容”列中,相应 Android Bug ID 旁边会显示 *。<em></em><a href="https://developers.google.com/android/nexus/drivers">Google Developers 网站</a>上针对 Nexus 设备提供的最新二进制驱动程序中通常包含旨在解决相应问题的更新。 |
| </p> |
| <p> |
| <strong>6. 为什么要将安全漏洞拆分到本公告和设备 / 合作伙伴安全公告(如 Pixel/Nexus 公告)中?</strong> |
| </p> |
| <p> |
| 要在 Android 设备上声明最新的安全补丁程序级别,必须修复本安全公告中记录的安全漏洞。但在声明安全补丁程序级别时,并不是必须要修复设备/合作伙伴安全公告中记录的其他安全漏洞。我们建议 Android 设备和芯片组制造商通过自己的安全网站(例如 <a href="https://security.samsungmobile.com/securityUpdate.smsb">Samsung</a>、<a href="https://lgsecurity.lge.com/security_updates.html">LGE</a> 或 <a href="/security/bulletin/pixel/">Pixel/Nexus</a> 安全公告)记录其设备上存在的其他修复程序。 |
| </p> |
| <h2 id="versions">版本</h2> |
| <table> |
| <colgroup><col width="25%" /> |
| <col width="25%" /> |
| <col width="50%" /> |
| </colgroup><tbody><tr> |
| <th>版本</th> |
| <th>日期</th> |
| <th>备注</th> |
| </tr> |
| <tr> |
| <td>1.0</td> |
| <td>2018 年 4 月 2 日</td> |
| <td>发布了本公告。</td> |
| </tr> |
| <tr> |
| <td>1.1</td> |
| <td>2018 年 4 月 4 日</td> |
| <td>在本公告中添加了 AOSP 链接。</td> |
| </tr> |
| <tr> |
| <td>1.2</td> |
| <td>2018 年 5 月 1 日</td> |
| <td>修订了本公告,从“内核组件”部分中移除了 CVE-2017-5754。这个 CVE 现在显示在 2018 年 5 月的公告中。</td> |
| </tr> |
| </tbody></table> |
| |
| </body></html> |