VYPR

Android

by Google

CVEs (8,504)

  • CVE-2016-4477HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or…

  • CVE-2016-2452HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by…

  • CVE-2016-2451HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate VPX output buffer sizes, which allows attackers to gain privileges via a crafted application, as…

  • CVE-2016-2450HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    codecs/on2/enc/SoftVPXEncoder.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafted application, as…

  • CVE-2016-2449HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    services/camera/libcameraservice/device3/Camera3Device.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate template IDs, which allows attackers to gain privileges via a crafted application, as…

  • CVE-2016-2448HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    media/libmediaplayerservice/nuplayer/NuPlayerStreamListener.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly validate entry data structures, which allows attackers to gain privileges via a crafted…

  • CVE-2016-2440HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    libs/binder/IPCThreadState.cpp in Binder in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 mishandles object references, which allows attackers to gain privileges via a crafted application, aka internal bug 27252896.

  • CVE-2016-2437HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.01

    The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27436822.

  • CVE-2016-2436HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27299111.

  • CVE-2016-2435HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.01

    The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27297988.

  • CVE-2016-2434HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.01

    The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27251090.

  • CVE-2016-2432HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059.

  • CVE-2016-2431HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.02

    The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 24968809.

  • CVE-2016-2430HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to gain privileges via an application containing a crafted symbol name, aka internal bug 27299236.

  • CVE-2016-2060HigMay 9, 2016
    risk 0.51cvss 7.8epss 0.00

    server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access…

  • CVE-2016-2422HigApr 18, 2016
    risk 0.51cvss 7.8epss 0.00

    Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not prevent use of a Wi-Fi CA certificate in an unrelated CA role, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining…

  • CVE-2016-2420HigApr 18, 2016
    risk 0.51cvss 7.8epss 0.00

    rootdir/init.rc in Android 4.x before 4.4.4 does not ensure that the /data/tombstones directory exists for the Debuggerd component, which allows attackers to gain privileges via a crafted application, aka internal bug 26403620.

  • CVE-2016-2413HigApr 18, 2016
    risk 0.51cvss 7.8epss 0.00

    media/libmedia/IOMX.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a handle pointer, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or…

  • CVE-2016-2412HigApr 18, 2016
    risk 0.51cvss 7.8epss 0.00

    include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01, mishandles certain crashes, which allows attackers to gain privileges via a crafted application, as demonstrated by…

  • CVE-2016-0836HigApr 18, 2016
    risk 0.51cvss 7.8epss 0.02

    Stack-based buffer overflow in decoder/impeg2d_vld.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25812590.

Page 169 of 426