Lucene search

K

Android Security Vulnerabilities

cve
cve

CVE-2016-11031

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. AntService allows a system_server crash and reboot. The Samsung ID is SVE-2016-7044 (November 2016).

7.5CVSS

7.6AI Score

0.001EPSS

2020-04-07 02:15 PM
24
cve
cve

CVE-2016-11032

An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotected intent. The Samsung IDs are SVE-2016-7179 and SVE-2016-7182 (November 2016).

5.3CVSS

5.4AI Score

0.001EPSS

2020-04-07 02:15 PM
21
cve
cve

CVE-2016-11033

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a heap-based buffer overflow in tlc_server. The Samsung IDs are SVE-2016-7220 and SVE-2016-7225 (November 2016).

9.8CVSS

9.7AI Score

0.001EPSS

2020-04-07 02:15 PM
21
cve
cve

CVE-2016-11034

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).

6.5CVSS

6.4AI Score

0.001EPSS

2020-04-07 02:15 PM
20
cve
cve

CVE-2016-11035

An issue was discovered on Samsung mobile devices with software through 2016-05-27 (Exynos AP chipsets). A local graphics user can cause a Kernel Crash via the fb0(DECON) frame buffer interface. The Samsung ID is SVE-2016-7011 (October 2016).

5.5CVSS

5.6AI Score

0.0004EPSS

2020-04-07 02:15 PM
15
cve
cve

CVE-2016-11036

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).

9.8CVSS

9.3AI Score

0.001EPSS

2020-04-07 02:15 PM
16
cve
cve

CVE-2016-11038

An issue was discovered on Samsung mobile devices with software through 2016-04-05 (incorporating the Samsung Professional Audio SDK). The Jack audio service doesn't implement access control for shared memory, leading to arbitrary code execution or privilege escalation. The Samsung ID is SVE-2016-5...

9.8CVSS

9.7AI Score

0.002EPSS

2020-04-07 02:15 PM
22
cve
cve

CVE-2016-11039

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (AP + CP MDM9x35, or Qualcomm Onechip) software. There is a NULL pointer dereference issue in the IPC socket code. The Samsung ID is SVE-2016-5980 (July 2016).

7.5CVSS

7.6AI Score

0.001EPSS

2020-04-07 02:15 PM
17
cve
cve

CVE-2016-11040

An issue was discovered on Samsung mobile devices with L(5.0/5.1) (with USB OTG MyFile2014_L_ESS support) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5068 (June 2016).

4.6CVSS

4.8AI Score

0.0005EPSS

2020-04-07 02:15 PM
17
cve
cve

CVE-2016-11041

An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending an AT command over USB. The Samsung ID is SVE-2015-5301 (June 2016).

4.6CVSS

5AI Score

0.0005EPSS

2020-04-07 01:15 PM
22
cve
cve

CVE-2016-11042

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (June 2016).

7.5CVSS

7.6AI Score

0.001EPSS

2020-04-07 01:15 PM
20
cve
cve

CVE-2016-11043

An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).

7.5CVSS

7.5AI Score

0.001EPSS

2020-04-07 01:15 PM
21
cve
cve

CVE-2016-11044

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).

7.8CVSS

7.6AI Score

0.0004EPSS

2020-04-07 01:15 PM
25
cve
cve

CVE-2016-11045

An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. The Gallery library allow memory corruption via a malformed image. The Samsung ID is SVE-2016-5317 (May 2016).

7.8CVSS

7.8AI Score

0.0005EPSS

2020-04-07 01:15 PM
18
cve
cve

CVE-2016-11046

An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reach the radio layer (aka RIL or RILD) to place calls or send SMS messages. The Samsung ID is SVE-2016-5733 (May 2016).

7.5CVSS

7.5AI Score

0.001EPSS

2020-04-07 01:15 PM
18
cve
cve

CVE-2016-11047

An issue was discovered on Samsung mobile devices with JBP(4.2) and KK(4.4) (Marvell chipsets) software. The ACIPC-MSOCKET driver allows local privilege escalation via a stack-based buffer overflow. The Samsung ID is SVE-2016-5393 (April 2016).

7.8CVSS

7.8AI Score

0.0004EPSS

2020-04-07 01:15 PM
20
cve
cve

CVE-2016-11048

An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-5421 (March 2016).

4.6CVSS

4.8AI Score

0.0005EPSS

2020-04-07 01:15 PM
24
cve
cve

CVE-2016-11049

An issue was discovered on Samsung mobile devices with software through 2016-01-16 (Shannon333/308/310 chipsets). The IMEI may be retrieved and modified because of an error in managing key information. The Samsung ID is SVE-2016-5435 (March 2016).

9.1CVSS

9.1AI Score

0.001EPSS

2020-04-07 01:15 PM
20
cve
cve

CVE-2016-11052

An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a malformed JPEG file. The Samsung ID is SVE-2015-5110 (January 2016).

7.8CVSS

7.7AI Score

0.0005EPSS

2020-04-07 01:15 PM
29
cve
cve

CVE-2016-11053

An issue was discovered on Samsung mobile devices with software through 2015-11-11 (supporting FRP/RL). There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5131 (January 2016).

4.6CVSS

4.8AI Score

0.0005EPSS

2020-04-07 01:15 PM
19
cve
cve

CVE-2016-1155

HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.

9.8CVSS

9.4AI Score

0.007EPSS

2017-04-13 05:59 PM
21
cve
cve

CVE-2016-1503

dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a malform...

9.8CVSS

8.8AI Score

0.047EPSS

2016-04-18 12:59 AM
24
cve
cve

CVE-2016-1621

libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452...

9.8CVSS

8.6AI Score

0.033EPSS

2016-03-12 09:59 PM
30
cve
cve

CVE-2016-1940

Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.

5.3CVSS

5.8AI Score

0.003EPSS

2016-01-31 06:59 PM
29
cve
cve

CVE-2016-1943

Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.

4.7CVSS

6.3AI Score

0.004EPSS

2016-01-31 06:59 PM
33
cve
cve

CVE-2016-1948

Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.

5.3CVSS

5.9AI Score

0.001EPSS

2016-01-31 06:59 PM
33
cve
cve

CVE-2016-2059

The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a client port, which allo...

7CVSS

7.4AI Score

0.001EPSS

2016-05-05 09:59 PM
36
4
cve
cve

CVE-2016-2060

server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access restrictions via a c...

7.8CVSS

7.3AI Score

0.001EPSS

2016-05-09 10:59 AM
26
cve
cve

CVE-2016-2067

drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows attackers to gain privileges by leveraging ...

7.8CVSS

7.4AI Score

0.001EPSS

2016-07-11 01:59 AM
49
4
cve
cve

CVE-2016-2068

The MSM QDSP6 audio driver (aka sound driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (integer overflow, and buffer overflow or buffer over-read)...

7.8CVSS

7.6AI Score

0.001EPSS

2016-07-11 01:59 AM
37
4
cve
cve

CVE-2016-2107

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exi...

5.9CVSS

6.9AI Score

0.968EPSS

2016-05-05 01:59 AM
510
4
cve
cve

CVE-2016-2108

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.

9.8CVSS

8.3AI Score

0.895EPSS

2016-05-05 01:59 AM
420
4
cve
cve

CVE-2016-2409

A Texas Instruments (TI) haptic kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control over a service that can call this driver, aka internal bug 25981545.

8.1CVSS

7.5AI Score

0.001EPSS

2016-04-18 12:59 AM
15
cve
cve

CVE-2016-2410

A Qualcomm video kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control over a service that can call this driver, aka internal bug 26291677.

7.4CVSS

7.2AI Score

0.001EPSS

2016-04-18 12:59 AM
19
cve
cve

CVE-2016-2411

A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages root access, aka internal bug 26866053.

6.5CVSS

6.4AI Score

0.0004EPSS

2016-04-18 12:59 AM
17
cve
cve

CVE-2016-2412

include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01, mishandles certain crashes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or Si...

7.8CVSS

7.5AI Score

0.001EPSS

2016-04-18 12:59 AM
14
cve
cve

CVE-2016-2413

media/libmedia/IOMX.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a handle pointer, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka inte...

7.8CVSS

7.5AI Score

0.001EPSS

2016-04-18 12:59 AM
17
cve
cve

CVE-2016-2414

The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177...

6.2CVSS

6.3AI Score

0.004EPSS

2016-04-18 12:59 AM
17
cve
cve

CVE-2016-2415

exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to obtain sensitive information via a crafted application that triggers a spoofed response to a GET request, aka ...

5.5CVSS

5.5AI Score

0.001EPSS

2016-04-18 12:59 AM
13
cve
cve

CVE-2016-2416

libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for the android.permission.DUMP permission, which allows attackers to obtain sensitive information, and consequently bypass an unspecified pr...

9.8CVSS

7.9AI Score

0.002EPSS

2016-04-18 12:59 AM
18
cve
cve

CVE-2016-2417

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified pr...

9.8CVSS

7.7AI Score

0.016EPSS

2016-04-18 12:59 AM
18
cve
cve

CVE-2016-2418

media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstr...

9.8CVSS

7.9AI Score

0.001EPSS

2016-04-18 12:59 AM
15
cve
cve

CVE-2016-2419

media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demo...

9.8CVSS

7.7AI Score

0.001EPSS

2016-04-18 12:59 AM
20
cve
cve

CVE-2016-2420

rootdir/init.rc in Android 4.x before 4.4.4 does not ensure that the /data/tombstones directory exists for the Debuggerd component, which allows attackers to gain privileges via a crafted application, aka internal bug 26403620.

7.8CVSS

7.4AI Score

0.001EPSS

2016-04-18 12:59 AM
19
cve
cve

CVE-2016-2421

Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.

6.1CVSS

6.2AI Score

0.001EPSS

2016-04-18 12:59 AM
23
cve
cve

CVE-2016-2422

Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not prevent use of a Wi-Fi CA certificate in an unrelated CA role, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSyst...

7.8CVSS

7.5AI Score

0.001EPSS

2016-04-18 12:59 AM
14
cve
cve

CVE-2016-2423

server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider whether a device is provisioned, which allows physically proximate attackers to bypass the Factory Reset Protection protection mech...

6.1CVSS

6.2AI Score

0.001EPSS

2016-04-18 12:59 AM
15
cve
cve

CVE-2016-2424

server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mismanages certain authority data, which allows attackers to cause a denial of service (reboot loop) via a crafted application, aka internal bug ...

5.5CVSS

5.6AI Score

0.001EPSS

2016-04-18 12:59 AM
18
cve
cve

CVE-2016-2425

mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 supports file:///data attachments, which allows attackers to obtain sensitive information via a crafted application, aka internal bugs 7154234 and 26989185.

5.5CVSS

5.6AI Score

0.001EPSS

2016-04-18 12:59 AM
17
cve
cve

CVE-2016-2426

server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a GET_ACCOUNTS permission, which allows attackers to obtain sensitive information via a crafted application, aka internal b...

5.5CVSS

5.5AI Score

0.001EPSS

2016-04-18 12:59 AM
17
Total number of security vulnerabilities7147