Lucene search

K

Android Security Vulnerabilities

cve
cve

CVE-2015-6619

The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, aka internal bug 23520714.

6.6AI Score

0.001EPSS

2015-12-08 11:59 PM
28
cve
cve

CVE-2015-6620

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 24123723 and 24445127.

7AI Score

0.001EPSS

2015-12-08 11:59 PM
23
cve
cve

CVE-2015-6621

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23909438.

6.8AI Score

0.001EPSS

2015-12-08 11:59 PM
22
cve
cve

CVE-2015-6622

The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal...

6.6AI Score

0.001EPSS

2015-12-08 11:59 PM
21
cve
cve

CVE-2015-6623

Wi-Fi in Android 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24872703.

6.8AI Score

0.001EPSS

2015-12-08 11:59 PM
24
cve
cve

CVE-2015-6624

System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23999740.

6AI Score

0.001EPSS

2015-12-08 11:59 PM
16
cve
cve

CVE-2015-6625

System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information and consequently gain privileges via a crafted application, aka internal bug 23936840.

6.2AI Score

0.001EPSS

2015-12-08 11:59 PM
18
cve
cve

CVE-2015-6626

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 243...

6.8AI Score

0.001EPSS

2015-12-08 11:59 PM
25
cve
cve

CVE-2015-6627

The Audio component in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information via a crafted audio file, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24211743.

6.2AI Score

0.001EPSS

2015-12-08 11:59 PM
17
cve
cve

CVE-2015-6628

Media Framework in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24074485.

6.6AI Score

0.001EPSS

2015-12-08 11:59 PM
24
cve
cve

CVE-2015-6629

Wi-Fi in Android 5.x before 5.1.1 LMY48Z allows attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22667667.

6.2AI Score

0.001EPSS

2015-12-08 11:59 PM
22
cve
cve

CVE-2015-6630

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to read screenshots and consequently gain privileges via a crafted application, aka internal bug 19121797.

6.6AI Score

0.001EPSS

2015-12-08 11:59 PM
22
cve
cve

CVE-2015-6631

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 246...

6.8AI Score

0.001EPSS

2015-12-08 11:59 PM
17
cve
cve

CVE-2015-6632

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 243...

6.8AI Score

0.001EPSS

2015-12-08 11:59 PM
17
cve
cve

CVE-2015-6633

The display drivers in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23987307.

7.9AI Score

0.002EPSS

2015-12-08 11:59 PM
21
cve
cve

CVE-2015-6634

The display drivers in Android before 5.1.1 LMY48Z allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24163261.

7.8AI Score

0.002EPSS

2015-12-08 11:59 PM
30
cve
cve

CVE-2015-6636

mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 25070493 and 24686670.

9.8CVSS

9.5AI Score

0.001EPSS

2016-01-06 07:59 PM
43
cve
cve

CVE-2015-6637

The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.

7.8CVSS

7.6AI Score

0.001EPSS

2016-01-06 07:59 PM
25
cve
cve

CVE-2015-6638

The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.

7.8CVSS

7.6AI Score

0.001EPSS

2016-01-06 07:59 PM
25
cve
cve

CVE-2015-6639

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.

7.8CVSS

7.5AI Score

0.003EPSS

2016-01-06 07:59 PM
66
2
cve
cve

CVE-2015-6640

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted applicat...

7.8CVSS

7.5AI Score

0.001EPSS

2016-01-06 07:59 PM
18
cve
cve

CVE-2015-6641

Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.

3.1CVSS

4.9AI Score

0.001EPSS

2016-01-06 07:59 PM
28
cve
cve

CVE-2015-6642

The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24157888.

9.8CVSS

8.9AI Score

0.001EPSS

2016-01-06 07:59 PM
22
cve
cve

CVE-2015-6643

Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.

6.6CVSS

6.9AI Score

0.0004EPSS

2016-01-06 07:59 PM
18
cve
cve

CVE-2015-6644

Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

3.3CVSS

3.4AI Score

0.002EPSS

2016-01-06 07:59 PM
53
cve
cve

CVE-2015-6645

SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a crafted application, aka internal bug 23591205.

5CVSS

5.7AI Score

0.0004EPSS

2016-01-06 07:59 PM
17
cve
cve

CVE-2015-6646

The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager, aka internal bug 22300191, a different vulnera...

6.2CVSS

5.7AI Score

0.001EPSS

2016-01-06 07:59 PM
30
cve
cve

CVE-2015-6647

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.

7.8CVSS

7.6AI Score

0.001EPSS

2016-01-06 07:59 PM
25
cve
cve

CVE-2015-6676

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspec...

7.7AI Score

0.035EPSS

2015-09-22 10:59 AM
39
cve
cve

CVE-2015-6677

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute arbitrary code or cause a denial of service (...

7.8AI Score

0.077EPSS

2015-09-22 10:59 AM
40
cve
cve

CVE-2015-6678

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspec...

7.7AI Score

0.035EPSS

2015-09-22 10:59 AM
36
cve
cve

CVE-2015-6682

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary co...

7.5AI Score

0.809EPSS

2015-09-22 10:59 AM
50
cve
cve

CVE-2015-6783

The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP ...

8.5AI Score

0.001EPSS

2015-12-06 01:59 AM
39
cve
cve

CVE-2015-7716

libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulnerability than CVE-2015-3873.

7.6AI Score

0.001EPSS

2015-10-06 05:59 PM
22
cve
cve

CVE-2015-7717

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.

6.5AI Score

0.001EPSS

2015-10-06 05:59 PM
20
cve
cve

CVE-2015-7718

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.

6.4AI Score

0.001EPSS

2015-10-06 05:59 PM
19
cve
cve

CVE-2015-7889

The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email address to obtain sensit...

5.5CVSS

5.6AI Score

0.004EPSS

2017-12-28 02:29 AM
19
cve
cve

CVE-2015-8072

mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23881715, a different vulnerability than CVE-2015-6608 and CVE-2015-8073...

7.6AI Score

0.002EPSS

2015-11-03 11:59 AM
17
cve
cve

CVE-2015-8073

mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 14388161, a different vulnerability than CVE-2015-6608 and CVE-2015-8072.

7.6AI Score

0.002EPSS

2015-11-03 11:59 AM
19
cve
cve

CVE-2015-8074

mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than CVE-2015-6611.

6.6AI Score

0.001EPSS

2015-11-03 11:59 AM
15
cve
cve

CVE-2015-8505

mediaserver in Android before 5.1.1 LMY48Z allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 17769851, a different vulnerability than CVE-2015-6616, CVE-2015-8506, and CVE-2015-8507.

7.5AI Score

0.002EPSS

2015-12-08 11:59 PM
18
cve
cve

CVE-2015-8506

mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24441553, a different vulnerability than CVE-2015-6616, CVE-2015-8505, and CVE-2015-8507...

7.5AI Score

0.002EPSS

2015-12-08 11:59 PM
21
cve
cve

CVE-2015-8507

mediaserver in Android 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24157524, a different vulnerability than CVE-2015-6616, CVE-2015-8505, and CVE-2015-8506.

7.5AI Score

0.002EPSS

2015-12-08 11:59 PM
19
cve
cve

CVE-2015-8546

An issue was discovered on Samsung mobile devices with software through 2015-11-12, affecting the Galaxy S6/S6 Edge, Galaxy S6 Edge+, and Galaxy Note5 with the Shannon333 chipset. There is a stack-based buffer overflow in the baseband process that is exploitable for remote code execution via a fake...

9.8CVSS

9.9AI Score

0.001EPSS

2020-04-10 07:15 PM
108
cve
cve

CVE-2015-8592

In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not validated prior to being dereferenced potentially resulting in Guest-OS memory corruption.

9.8CVSS

7.7AI Score

0.001EPSS

2017-08-18 06:29 PM
15
cve
cve

CVE-2015-8593

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.

9.8CVSS

9AI Score

0.002EPSS

2018-04-02 12:00 AM
23
cve
cve

CVE-2015-8594

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in RFA-1x.

9.8CVSS

8.8AI Score

0.002EPSS

2018-04-02 12:00 AM
16
cve
cve

CVE-2015-8595

In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in digital television/digital radio DRM.

9.8CVSS

7.9AI Score

0.001EPSS

2017-08-18 06:29 PM
17
cve
cve

CVE-2015-8596

In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of buffer lengths is missing in malware protection.

9.8CVSS

7.9AI Score

0.001EPSS

2017-08-18 06:29 PM
25
cve
cve

CVE-2015-8888

Integer overflow in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows attackers to bypass intended access restrictions via a crafted block count and block size of a sparse header, aka Android internal bug 28822465 and Qualcomm internal bug CR813933.

7.8CVSS

7.5AI Score

0.001EPSS

2016-07-11 01:59 AM
16
4
Total number of security vulnerabilities7147