Lucene search

K

Android Security Vulnerabilities

cve
cve

CVE-2016-0807

The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug 25187394.

8.4CVSS

8.1AI Score

0.001EPSS

2016-02-07 01:59 AM
30
cve
cve

CVE-2016-0808

Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka inter...

6.2CVSS

6.5AI Score

0.001EPSS

2016-02-07 01:59 AM
20
cve
cve

CVE-2016-0809

Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers to gain privileges by leveraging access to the local physical environment during execution of a crafted application, aka internal bug 25753768.

8.8CVSS

8.5AI Score

0.001EPSS

2016-02-07 01:59 AM
25
cve
cve

CVE-2016-0810

media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 mishandles locking requirements, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka i...

7.8CVSS

8AI Score

0.001EPSS

2016-02-07 01:59 AM
28
cve
cve

CVE-2016-0811

Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an improper size calculation, as...

7.5CVSS

8AI Score

0.001EPSS

2016-02-07 01:59 AM
18
cve
cve

CVE-2016-0812

The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does not properly check for setup completion, which allows physically proximate attackers to bypass the Fa...

6.1CVSS

6.6AI Score

0.001EPSS

2016-02-07 01:59 AM
13
cve
cve

CVE-2016-0813

packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before 2016-02-01 does not properly check for device provisioning, which allows physically proximate attackers to bypass the Factory Reset Protection protec...

6.1CVSS

6.6AI Score

0.001EPSS

2016-02-07 01:59 AM
16
cve
cve

CVE-2016-0815

The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file...

9.8CVSS

8.8AI Score

0.006EPSS

2016-03-12 09:59 PM
17
cve
cve

CVE-2016-0816

mediaserver in Android 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to decoder/ih264d_parse_islice.c and decoder/ih264d_parse_pslice.c, aka internal bug 25928803.

9.8CVSS

8.8AI Score

0.006EPSS

2016-03-12 09:59 PM
19
cve
cve

CVE-2016-0818

The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoo...

5.9CVSS

5.6AI Score

0.001EPSS

2016-03-12 09:59 PM
28
cve
cve

CVE-2016-0819

The Qualcomm performance component in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 25364034.

7.8CVSS

7.4AI Score

0.001EPSS

2016-03-12 09:59 PM
28
2
cve
cve

CVE-2016-0820

The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 26267358.

7.8CVSS

7.2AI Score

0.001EPSS

2016-03-12 09:59 PM
27
cve
cve

CVE-2016-0821

The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the...

5.5CVSS

6AI Score

0.001EPSS

2016-03-12 09:59 PM
91
cve
cve

CVE-2016-0822

The MediaTek connectivity kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application that leverages conn_launcher access, aka internal bug 25873324.

7CVSS

6.8AI Score

0.001EPSS

2016-03-12 09:59 PM
17
cve
cve

CVE-2016-0823

The pagemap_open function in fs/proc/task_mmu.c in the Linux kernel before 3.19.3, as used in Android 6.0.1 before 2016-03-01, allows local users to obtain sensitive physical-address information by reading a pagemap file, aka Android internal bug 25739721.

4CVSS

5.3AI Score

0.001EPSS

2016-03-12 09:59 PM
58
cve
cve

CVE-2016-0824

libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25765591.

5.3CVSS

5.7AI Score

0.001EPSS

2016-03-12 09:59 PM
18
cve
cve

CVE-2016-0825

The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 20860039.

5.3CVSS

5.4AI Score

0.001EPSS

2016-03-12 09:59 PM
28
cve
cve

CVE-2016-0826

libcameraservice in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not require use of the ICameraService::dump method for a camera service dump, which allows attackers to gain privileges via a crafted application that directly dumps, as demonstrated...

7.8CVSS

7.5AI Score

0.001EPSS

2016-03-12 09:59 PM
15
cve
cve

CVE-2016-0827

Multiple integer overflows in libeffects in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, related to EffectBundle.cpp and E...

7.8CVSS

7.5AI Score

0.001EPSS

2016-03-12 09:59 PM
19
cve
cve

CVE-2016-0828

The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not initialize a certain slot variable, which allows attackers to obtain sensitive information, and consequently bypass an unspeci...

7.5CVSS

7.3AI Score

0.001EPSS

2016-03-12 09:59 PM
28
cve
cve

CVE-2016-0829

The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, which allows attackers to obtain sensitive information, and con...

7.5CVSS

7.3AI Score

0.001EPSS

2016-03-12 09:59 PM
24
cve
cve

CVE-2016-0830

btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denial of service (memory corruption and persistent daemon crash) by triggering a large number of configuration entries, and consequently exceeding the maximum size of a configuration file, aka internal b...

6.5CVSS

6.5AI Score

0.004EPSS

2016-03-12 09:59 PM
16
cve
cve

CVE-2016-0831

The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows attackers to obtain sensitive information via a crafted application, aka inte...

5.5CVSS

5.5AI Score

0.001EPSS

2016-03-12 09:59 PM
15
cve
cve

CVE-2016-0832

Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25955042.

6.1CVSS

6.2AI Score

0.001EPSS

2016-03-12 09:59 PM
17
cve
cve

CVE-2016-0833

Android allows users to cause a denial of service.

7.5CVSS

7.2AI Score

0.001EPSS

2017-04-21 02:59 PM
16
cve
cve

CVE-2016-0834

An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26220548.

8.4CVSS

8.1AI Score

0.001EPSS

2016-04-18 12:59 AM
25
cve
cve

CVE-2016-0835

decoder/impeg2d_dec_hdr.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a certain negative value, aka internal bug 26070014.

9.8CVSS

8.8AI Score

0.006EPSS

2016-04-18 12:59 AM
20
cve
cve

CVE-2016-0836

Stack-based buffer overflow in decoder/impeg2d_vld.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25812590.

7.8CVSS

8AI Score

0.001EPSS

2016-04-18 12:59 AM
16
cve
cve

CVE-2016-0837

MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via a crafted media file, aka ...

9.8CVSS

8.8AI Score

0.001EPSS

2016-04-18 12:59 AM
27
cve
cve

CVE-2016-0838

Sonivox in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a negative number of samples, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, r...

9.8CVSS

8.8AI Score

0.006EPSS

2016-04-18 12:59 AM
16
cve
cve

CVE-2016-0839

post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25753245.

9.8CVSS

8.8AI Score

0.001EPSS

2016-04-18 12:59 AM
16
cve
cve

CVE-2016-0840

Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26399350.

8.4CVSS

8.2AI Score

0.001EPSS

2016-04-18 12:59 AM
16
cve
cve

CVE-2016-0841

media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a ...

9.8CVSS

8.8AI Score

0.001EPSS

2016-04-18 12:59 AM
19
cve
cve

CVE-2016-0842

The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25818142.

8.4CVSS

8.2AI Score

0.001EPSS

2016-04-18 12:59 AM
22
cve
cve

CVE-2016-0843

The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application, aka internal bug 25801197.

8.4CVSS

7.8AI Score

0.001EPSS

2016-04-18 12:59 AM
15
cve
cve

CVE-2016-0844

The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privileges via a crafted application, aka internal bug 26324307.

8.4CVSS

7.8AI Score

0.001EPSS

2016-04-18 12:59 AM
15
cve
cve

CVE-2016-0846

libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider the heap size, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signatur...

8.4CVSS

7.8AI Score

0.001EPSS

2016-04-18 12:59 AM
16
cve
cve

CVE-2016-0847

The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to spoof the originating telephone number of a call via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26864502.

8.4CVSS

7.5AI Score

0.001EPSS

2016-04-18 12:59 AM
18
cve
cve

CVE-2016-0848

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or Si...

8.4CVSS

7.5AI Score

0.001EPSS

2016-04-18 12:59 AM
18
cve
cve

CVE-2016-0849

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26...

8.4CVSS

7.8AI Score

0.001EPSS

2016-04-18 12:59 AM
17
cve
cve

CVE-2016-0850

The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to bypass intended pairing restrictions via a crafted device, aka internal bug 26551752.

8.8CVSS

7.5AI Score

0.001EPSS

2016-04-18 12:59 AM
14
cve
cve

CVE-2016-10044

The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.

7.8CVSS

7.3AI Score

0.0004EPSS

2017-02-07 07:59 AM
91
cve
cve

CVE-2016-10200

Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/...

7CVSS

6.8AI Score

0.0004EPSS

2017-03-07 09:59 PM
122
cve
cve

CVE-2016-10229

udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

9.8CVSS

9.2AI Score

0.048EPSS

2017-04-04 05:59 AM
195
4
cve
cve

CVE-2016-10230

A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.

9.8CVSS

9.3AI Score

0.006EPSS

2018-04-04 06:29 PM
24
2
cve
cve

CVE-2016-10231

An elevation of privilege vulnerability in the Qualcomm sound codec driver. Product: Android. Versions: Android kernel. Android ID: A-33966912. References: QC-CR#1096799.

7.8CVSS

8AI Score

0.001EPSS

2018-04-04 06:29 PM
15
4
cve
cve

CVE-2016-10232

An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34386696. References: QC-CR#1024872.

7.8CVSS

8AI Score

0.001EPSS

2018-04-04 06:29 PM
18
4
cve
cve

CVE-2016-10233

An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34389926. References: QC-CR#897452.

9.8CVSS

9AI Score

0.003EPSS

2018-04-04 06:29 PM
17
4
cve
cve

CVE-2016-10234

An information disclosure vulnerability in the Qualcomm IPA driver. Product: Android. Versions: Android kernel. Android ID: A-34390017. References: QC-CR#1069060.

5.5CVSS

5.8AI Score

0.001EPSS

2018-04-04 06:29 PM
16
4
cve
cve

CVE-2016-10235

A denial of service vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-34390620. References: QC-CR#1046409.

7.5CVSS

7.4AI Score

0.003EPSS

2018-04-04 06:29 PM
19
Total number of security vulnerabilities7147