|
6641
|
8.4
7.2
|
HIGH
Local
|
Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted …
|
CWE-189
Numeric Errors
|
CVE-2016-0849
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6642
|
8.4
7.2
|
HIGH
Local
|
Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions v…
|
CWE-362
Race Condition
|
CVE-2016-0848
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6643
|
8.4
7.2
|
HIGH
Local
|
The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to spoof the originating telephone number of a call via a crafted application, as d…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0847
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6644
|
8.4
7.2
|
HIGH
Local
|
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider the heap size, which …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0846
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6645
|
8.4
7.2
|
HIGH
Local
|
The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privileges via a crafted application, aka internal bug …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0844
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6646
|
8.4
7.2
|
HIGH
Local
|
The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to gain privileges via a crafted a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0843
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6647
|
8.4
10.0
|
HIGH
Local
|
The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a den…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0842
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6648
|
9.8
10.0
|
CRITICAL
Network
|
media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allow…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0841
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:* cpe:2.3:o:google:android:5.1:* cpe:2.3:o:googl…
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6649
|
8.4
10.0
|
HIGH
Local
|
Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (m…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0840
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6650
|
9.8
10.0
|
CRITICAL
Network
|
post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (me…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-0839
|
cpe:2.3:o:google:android:6.0:* cpe:2.3:o:google:android:6.0.1:*
|
|
|
|
|
2024-11-21 11:42
2016-04-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|