|
6671
|
5.9
4.3
|
MEDIUM
Network
|
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinctio…
|
CWE-254 CWE-345
7PK - Security Features Insufficient Verification of Data Authenticity
|
CVE-2016-0818
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-03-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6672
|
9.8
10.0
|
CRITICAL
Network
|
mediaserver in Android 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to decoder/ih264d_par…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0816
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:42
2016-03-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6673
|
9.8
10.0
|
CRITICAL
Network
|
The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows remote attackers…
|
CWE-20
Improper Input Validation
|
CVE-2016-0815
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-03-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6674
|
9.8
10.0
|
CRITICAL
Network
|
Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory…
|
NVD-CWE-Other
|
CVE-2016-0705
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6675
|
7.8
7.2
|
HIGH
Local
|
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or…
|
NVD-CWE-Other
|
CVE-2016-0728
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-02-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6676
|
6.1
6.6
|
MEDIUM
Physics
|
packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before 2016-02-01 does not properly check for device pro…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0813
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-02-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6677
|
6.1
6.6
|
MEDIUM
Physics
|
The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does n…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0812
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-02-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6678
|
7.5
7.8
|
HIGH
Network
|
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and con…
|
CWE-200
Information Exposure
|
CVE-2016-0811
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:42
2016-02-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6679
|
7.8
6.9
|
HIGH
Local
|
media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 mishandles locking requirements, which allows attackers to gain privileges …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0810
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-02-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6680
|
8.8
8.3
|
HIGH
Adjacent
|
Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers to gain privileges by leveraging access to the loc…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0809
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:42
2016-02-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|