|
211681
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
|
CWE-284
Improper Access Control
|
CVE-2015-9021
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211682
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9020
|
2024-11-21 11:39 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211683
|
6.1 |
MEDIUM
Network
|
mail_project
|
mail
|
The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences imm…
|
CWE-93
CRLF Injection
|
CVE-2015-9097
|
2024-11-21 11:39 |
2017-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211684
|
6.1 |
MEDIUM
Network
|
ruby-lang
|
ruby
|
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA subs…
|
CWE-93
CRLF Injection
|
CVE-2015-9096
|
2024-11-21 11:39 |
2017-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211685
|
7.8 |
HIGH
Local
|
google
|
android
|
In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.
|
CWE-415
Double Free
|
CVE-2015-9007
|
2024-11-21 11:39 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211686
|
7.8 |
HIGH
Local
|
google
|
android
|
In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially exist.
|
CWE-284
Improper Access Control
|
CVE-2015-9006
|
2024-11-21 11:39 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211687
|
7.8 |
HIGH
Local
|
google
|
android
|
In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2015-9005
|
2024-11-21 11:39 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211688
|
9.8 |
CRITICAL
Network
|
picocom_project
|
picocom
|
picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.
|
CWE-77
Command Injection
|
CVE-2015-9059
|
2024-11-21 11:39 |
2017-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211689
|
7.8 |
HIGH
Local
|
google
|
android
|
In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.
|
CWE-310
Cryptographic Issues
|
CVE-2015-9003
|
2024-11-21 11:39 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211690
|
7.8 |
HIGH
Local
|
google
|
android
|
In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.
|
CWE-189
Numeric Errors
|
CVE-2015-9002
|
2024-11-21 11:39 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|