|
6421
|
5.5
4.3
|
MEDIUM
Local
|
Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 287…
|
CWE-284
Improper Access Control
|
CVE-2016-3838
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6422
|
5.5
4.3
|
MEDIUM
Local
|
service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted…
|
CWE-200
Information Exposure
|
CVE-2016-3837
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6423
|
5.5
4.3
|
MEDIUM
Local
|
The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of …
|
CWE-200
Information Exposure
|
CVE-2016-3836
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6424
|
5.5
4.3
|
MEDIUM
Local
|
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, …
|
CWE-200
Information Exposure
|
CVE-2016-3835
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6425
|
5.5
4.3
|
MEDIUM
Local
|
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information …
|
CWE-200
Information Exposure
|
CVE-2016-3834
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6426
|
7.8
9.3
|
HIGH
Local
|
The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3833
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6427
|
7.8
8.3
|
HIGH
Local
|
The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows att…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3832
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6428
|
7.5
5.0
|
HIGH
Network
|
The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ t…
|
CWE-20
Improper Input Validation
|
CVE-2016-3831
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6429
|
5.5
7.1
|
MEDIUM
Local
|
codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of…
|
CWE-20
Improper Input Validation
|
CVE-2016-3830
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6430
|
5.5
7.1
|
MEDIUM
Local
|
The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (device hang or reboot) vi…
|
CWE-172
Encoding Error
|
CVE-2016-3829
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:50
2016-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|