Google Security Advisories · August 2016 — Google Security Advisories
117 advisories 112 CVEs 10 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-6366

GoogleExploitedCISA KEV listedHIGH2016-08-18

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute ar...

CVEs:CVE-2016-6366

Affected products

ProductStatusVendorPackageEcosystem
adaptive_security_appliance_software affected cisco
asa_1000v_cloud_firewall_software affected cisco
pix_firewall_software affected cisco
Upstream advisory

CVE-2016-6366

Project ZeroExploitedCISA KEV listed2016-08-17

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

CVEs:CVE-2016-6366

Upstream advisory

CVE-2016-4657

GoogleExploitedCISA KEV listedCRITICAL2016-08-25

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVEs:CVE-2016-4657

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2016-4657

Project ZeroExploitedCISA KEV listed2016-08-25

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVEs:CVE-2016-4657

Upstream advisory

CVE-2016-4655

Project ZeroExploitedCISA KEV listed2016-08-25

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

CVEs:CVE-2016-4655

Upstream advisory

CVE-2016-4655

GoogleExploitedCISA KEV listedHIGH2016-08-25

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

CVEs:CVE-2016-4655

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2016-4656

GoogleExploitedCISA KEV listedHIGH2016-08-25

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVEs:CVE-2016-4656

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2016-4656

Project ZeroExploitedCISA KEV listed2016-08-25

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVEs:CVE-2016-4656

Upstream advisory

CVE-2016-6367

GoogleExploitedCISA KEV listedHIGH2016-08-18

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

CVEs:CVE-2016-6367

Affected products

ProductStatusVendorPackageEcosystem
adaptive_security_appliance_software affected cisco
Upstream advisory

CVE-2016-6367

Project ZeroExploitedCISA KEV listed2016-08-18

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

CVEs:CVE-2016-6367

Upstream advisory

RHSA-2016:1538

Open SourceWeaponized exploitMEDIUM2016-08-02

Red Hat Security Advisory: golang security, bug fix, and enhancement update

Affected products

ProductStatusVendorPackageEcosystem
golang affected Red Hat:enterprise_linux:7::server golang
golang-bin affected Red Hat:enterprise_linux:7::server golang-bin
golang-docs affected Red Hat:enterprise_linux:7::server golang-docs
golang-misc affected Red Hat:enterprise_linux:7::server golang-misc
golang-src affected Red Hat:enterprise_linux:7::server golang-src
golang-tests affected Red Hat:enterprise_linux:7::server golang-tests
Upstream advisory

CVE-2016-5696

Open SourcePoC exploitMEDIUM2016-08-01

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVEs:CVE-2016-5696

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
vm_server affected oracle
Upstream advisory

MGASA-2016-0274

Open SourcePoC exploitCRITICAL2016-08-03

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

CVE-2016-3857

Open SourcePoC exploitHIGH2016-08-01

The kernel in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 28522518.

CVEs:CVE-2016-3857

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9900

Open SourcePoC exploitMEDIUM2016-08-02

The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive informa...

CVEs:CVE-2014-9900

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-5342

Open SourcePoC exploitCRITICAL2016-08-30

Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and othe...

CVEs:CVE-2016-5342

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-5340

Open SourcePoC exploitHIGH2016-08-07

The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass ...

CVEs:CVE-2016-5340

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2014-9902

Open SourceEPSS <= 49%HIGH2016-08-02

Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 manageme...

CVEs:CVE-2014-9902

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3840

Open SourceEPSS <= 49%HIGH2016-08-02

Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.

CVEs:CVE-2016-3840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MGASA-2016-0279

Open SourceEPSS <= 49%CRITICAL2016-08-09

Updated chromium-browser-stable packages fix security vulnerability

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

DSA-3645-1

Open SourceEPSS <= 49%2016-08-09

chromium-browser - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Debian:8 chromium-browser
Upstream advisory

openSUSE-SU-2016:1982-1

Open SourceEPSS <= 49%CRITICAL2016-08-07

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

openSUSE-SU-2016:1983-1

Open SourceEPSS <= 49%CRITICAL2016-08-07

Security update for Chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

CVE-2016-5140

GoogleEPSS <= 49%CRITICAL2016-08-04

Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted ...

CVEs:CVE-2016-5140

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5143

GoogleEPSS <= 49%CRITICAL2016-08-04

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access re...

CVEs:CVE-2016-5143

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-3821

Open SourceEPSS <= 49%CRITICAL2016-08-02

libmedia in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 has certain incorrect declarations, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointe...

CVEs:CVE-2016-3821

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3819

Open SourceEPSS <= 49%CRITICAL2016-08-02

Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to execute arbitrary code or cause a den...

CVEs:CVE-2016-3819

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5344

Open SourceEPSS <= 49%CRITICAL2016-08-30

Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified oth...

CVEs:CVE-2016-5344

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-5144

GoogleEPSS <= 49%CRITICAL2016-08-04

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access re...

CVEs:CVE-2016-5144

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5142

GoogleEPSS <= 49%CRITICAL2016-08-04

The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifi...

CVEs:CVE-2016-5142

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5141

GoogleEPSS <= 49%HIGH2016-08-04

Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an initially empty document, related to FrameLoader.cpp and ScopedPageLoadDeferrer.cpp.

CVEs:CVE-2016-5141

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5146

GoogleEPSS <= 49%CRITICAL2016-08-04

Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVEs:CVE-2016-5146

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5145

GoogleEPSS <= 49%HIGH2016-08-04

Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, which allows remote attackers to bypass the Same Orig...

CVEs:CVE-2016-5145

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-3820

Open SourceEPSS <= 49%CRITICAL2016-08-02

The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 mishandles slice numbers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28673410.

CVEs:CVE-2016-3820

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5139

GoogleEPSS <= 49%CRITICAL2016-08-04

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified ot...

CVEs:CVE-2016-5139

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-3822

Open SourceEPSS <= 49%CRITICAL2016-08-02

exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds acce...

CVEs:CVE-2016-3822

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

CVE-2014-9870

Open SourceEPSS <= 49%HIGH2016-08-02

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted applic...

CVEs:CVE-2014-9870

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2014-9901

Open SourceEPSS <= 49%HIGH2016-08-01

The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cause a denial of service (device hang or reboot) via crafted frames, aka Android internal bug 28670333 an...

CVEs:CVE-2014-9901

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3843

Open SourceEPSS <= 49%HIGH2016-08-01

Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, ak...

CVEs:CVE-2016-3843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3831

Open SourceEPSS <= 49%HIGH2016-08-02

The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ time value of 2038-01-19 or later that is mishandled b...

CVEs:CVE-2016-3831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9895

Open SourceEPSS <= 49%MEDIUM2016-08-02

drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize certain data structures, which allows local users to obtain sensitive information via a cra...

CVEs:CVE-2014-9895

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-3829

Open SourceEPSS <= 49%HIGH2016-08-02

The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29023649.

CVEs:CVE-2016-3829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-2497

Open SourceEPSS <= 49%HIGH2016-08-02

services/core/java/com/android/server/pm/PackageManagerService.java in the framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to increase intent-filter priority via a crafted a...

CVEs:CVE-2016-2497

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8944

Open SourceEPSS <= 49%HIGH2016-08-02

The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information by...

CVEs:CVE-2015-8944

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-3827

Open SourceEPSS <= 49%HIGH2016-08-02

codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 288...

CVEs:CVE-2016-3827

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3828

Open SourceEPSS <= 49%HIGH2016-08-02

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.

CVEs:CVE-2016-3828

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3830

Open SourceEPSS <= 49%HIGH2016-08-02

codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device hang or reboot) via crafted ADTS dat...

CVEs:CVE-2016-3830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9871

Open SourceEPSS <= 49%HIGH2016-08-01

Multiple buffer overflows in drivers/media/platform/msm/camera_v2/isp/msm_isp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android inter...

CVEs:CVE-2014-9871

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9869

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/media/platform/msm/camera_v2/isp/msm_isp_stats_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain index values, which allows attackers to gain privileges via a crafted applic...

CVEs:CVE-2014-9869

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8938

Open SourceEPSS <= 49%HIGH2016-08-02

The MSM camera driver in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices does not validate input parameters, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28804030 and Qualcomm int...

CVEs:CVE-2015-8938

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8940

Open SourceEPSS <= 49%HIGH2016-08-02

Integer overflow in sound/soc/msm/qdsp6v2/q6lsm.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28813987 and Qualcomm internal bug CR79...

CVEs:CVE-2015-8940

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9863

Open SourceEPSS <= 49%HIGH2016-08-01

Integer underflow in the diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android internal bug 2876814...

CVEs:CVE-2014-9863

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9864

Open SourceEPSS <= 49%HIGH2016-08-01

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate ioctl calls, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28747998 and Qua...

CVEs:CVE-2014-9864

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9866

Open SourceEPSS <= 49%HIGH2016-08-01

drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate a certain parameter, which allows attackers to gain privileges via a crafted applicati...

CVEs:CVE-2014-9866

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9867

Open SourceEPSS <= 49%HIGH2016-08-01

drivers/media/platform/msm/camera_v2/isp/msm_isp_axi_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate the number of streams, which allows attackers to gain privileges via a crafted applica...

CVEs:CVE-2014-9867

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-3854

Open SourceEPSS <= 49%HIGH2016-08-07

packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.

CVEs:CVE-2015-3854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8942

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices does not validate the stream state, which allows attackers to gain privileges via a crafted application, aka Android int...

CVEs:CVE-2015-8942

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9887

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain length values, which allows attackers to gain privileges via a crafted application, aka Android internal bug 288040...

CVEs:CVE-2014-9887

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9890

Open SourceEPSS <= 49%HIGH2016-08-02

Off-by-one error in drivers/media/platform/msm/camera_v2/sensor/cci/msm_cci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application that sends an I2C comman...

CVEs:CVE-2014-9890

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9891

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate certain buffer addresses, which allows attackers to gain privileges via a crafted application that makes an ioctl call, aka Android inte...

CVEs:CVE-2014-9891

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8939

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/video/msm/mdp4_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not validate r stages, g stages, or b stages data, which allows attackers to gain privileges via a crafted application, aka Android int...

CVEs:CVE-2015-8939

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8941

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/media/platform/msm/camera_v2/isp/msm_isp_axi_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices does not properly validate array indexes, which allows attackers to gain privileges via a crafted applic...

CVEs:CVE-2015-8941

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3851

Open SourceEPSS <= 49%HIGH2016-08-01

The LG Electronics bootloader Android before 2016-08-05 on Nexus 5X devices allows attackers to gain privileges by leveraging access to a privileged process, aka internal bug 29189941.

CVEs:CVE-2016-3851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9865

Open SourceEPSS <= 49%HIGH2016-08-01

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly restrict user-space input, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28...

CVEs:CVE-2014-9865

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9882

Open SourceEPSS <= 49%CRITICAL2016-08-02

Buffer overflow in drivers/media/radio/radio-iris.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28769546 and Qualcomm internal...

CVEs:CVE-2014-9882

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9892

Open SourceEPSS <= 49%HIGH2016-08-02

The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obt...

CVEs:CVE-2014-9892

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2014-9881

Open SourceEPSS <= 49%CRITICAL2016-08-02

drivers/media/radio/radio-iris.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices uses an incorrect integer data type, which allows attackers to gain privileges or cause a denial of service (buffer overflow) via a craft...

CVEs:CVE-2014-9881

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9874

Open SourceEPSS <= 49%CRITICAL2016-08-01

Buffer overflow in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, related to arch/arm/mach-msm/qdsp6v2/audio_utils.c and sound/soc/msm/qdsp6v2...

CVEs:CVE-2014-9874

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3833

Open SourceEPSS <= 49%HIGH2016-08-02

The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypass intended access restrictions via a crafted applica...

CVEs:CVE-2016-3833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3856

Open SourceEPSS <= 49%HIGH2016-08-02

netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR959631.

CVEs:CVE-2016-3856

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9876

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/char/diag/diagfwd.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices mishandles certain integer values, which allows attackers to gain privileges via a crafted application, aka Android internal...

CVEs:CVE-2014-9876

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8937

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/char/diag/diagchar_core.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 6, and 7 (2013) devices mishandles a socket process, which allows attackers to gain privileges via a crafted application, aka Android internal bug 288...

CVEs:CVE-2015-8937

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3835

Open SourceEPSS <= 49%HIGH2016-08-02

The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to obtain sensitive informatio...

CVEs:CVE-2016-3835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9893

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not properly determine the size of Gamut LUT data, which allows attackers to obtain sensitive information via a crafted application, ak...

CVEs:CVE-2014-9893

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9894

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not ensure that certain name strings end in a '\0' character, which allows attackers to obtain sensitive information via a crafted application...

CVEs:CVE-2014-9894

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9896

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/char/adsprpc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate parameters and return values, which allows attackers to obtain sensitive information via a crafted application, ak...

CVEs:CVE-2014-9896

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9897

Open SourceEPSS <= 49%HIGH2016-08-02

sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate certain user-space data, which allows attackers to obtain sensitive information via a crafted application, aka Android i...

CVEs:CVE-2014-9897

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9898

Open SourceEPSS <= 49%HIGH2016-08-02

arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate input parameters, which allows attackers to obtain sensitive information via a crafted applica...

CVEs:CVE-2014-9898

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9899

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/usb/host/ehci-msm2.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices omits certain minimum calculations before copying data, which allows attackers to obtain sensitive information via a crafted application, aka Androi...

CVEs:CVE-2014-9899

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9877

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices mishandles a user-space pointer, which allows attackers to gain privileges via a crafted applica...

CVEs:CVE-2014-9877

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9878

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/mmc/card/mmc_block_test.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not reject kernel-space buffer addresses, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28...

CVEs:CVE-2014-9878

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9879

Open SourceEPSS <= 49%HIGH2016-08-02

The mdss mdp3 driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate user-space data, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769221 and Qualcomm inter...

CVEs:CVE-2014-9879

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9880

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/video/msm/vidc/common/enc/venc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not validate VEN_IOCTL_GET_SEQUENCE_HDR ioctl calls, which allows attackers to gain privileges via a crafted application, ak...

CVEs:CVE-2014-9880

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9883

Open SourceEPSS <= 49%CRITICAL2016-08-02

Integer overflow in drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android internal...

CVEs:CVE-2014-9883

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9884

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain pointers, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769920 an...

CVEs:CVE-2014-9884

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9885

Open SourceEPSS <= 49%HIGH2016-08-02

Format string vulnerability in drivers/thermal/qpnp-adc-tm.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application that provides format string specifiers in a name, aka ...

CVEs:CVE-2014-9885

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9886

Open SourceEPSS <= 49%HIGH2016-08-02

arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate input parameters, which allows attackers to gain privileges via a crafted application, aka And...

CVEs:CVE-2014-9886

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9889

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate CPP frame messages, which allows attackers to gain privileges via a crafted application, aka Android i...

CVEs:CVE-2014-9889

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2015-8943

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/video/msm/mdss/mdss_mdp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not verify that a mapping exists before proceeding with an unmap operation, which allows attackers to gain privileges via a crafted a...

CVEs:CVE-2015-8943

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3836

Open SourceEPSS <= 49%HIGH2016-08-02

The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka...

CVEs:CVE-2016-3836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3837

Open SourceEPSS <= 49%HIGH2016-08-02

service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application that provides a MAC address with too few...

CVEs:CVE-2016-3837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9872

Open SourceEPSS <= 49%HIGH2016-08-01

The diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not ensure unique identifiers in a DCI client table, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28750155 ...

CVEs:CVE-2014-9872

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9873

Open SourceEPSS <= 49%HIGH2016-08-01

Integer underflow in drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android interna...

CVEs:CVE-2014-9873

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9875

Open SourceEPSS <= 49%HIGH2016-08-01

drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application that sends short DCI request packets, aka Android internal bug 28767589 and Qua...

CVEs:CVE-2014-9875

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3839

Open SourceEPSS <= 49%HIGH2016-08-02

Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a crafted application that sends a signal to a Bluetooth pr...

CVEs:CVE-2016-3839

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3844

Open SourceEPSS <= 49%HIGH2016-08-01

mediaserver in Android before 2016-08-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28299517.

CVEs:CVE-2016-3844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3832

Open SourceEPSS <= 49%HIGH2016-08-02

The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows attackers to bypass an unspecified protection mechanism ...

CVEs:CVE-2016-3832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3842

Open SourceEPSS <= 49%HIGH2016-08-02

The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28377352 and Qualcomm internal bug CR1002974.

CVEs:CVE-2016-3842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3845

Open SourceEPSS <= 49%HIGH2016-08-01

The video driver in the kernel in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28399876.

CVEs:CVE-2016-3845

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3834

Open SourceEPSS <= 49%HIGH2016-08-01

The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application,...

CVEs:CVE-2016-3834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3854

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact ...

CVEs:CVE-2016-3854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3855

Open SourceEPSS <= 49%HIGH2016-08-02

drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other im...

CVEs:CVE-2016-3855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3838

Open SourceEPSS <= 49%HIGH2016-08-02

Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.

CVEs:CVE-2016-3838

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3846

Open SourceEPSS <= 49%HIGH2016-08-01

The Serial Peripheral Interface driver in Android before 2016-08-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28817378.

CVEs:CVE-2016-3846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3848

Open SourceEPSS <= 49%HIGH2016-08-01

The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28919417.

CVEs:CVE-2016-3848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3852

Open SourceEPSS <= 49%HIGH2016-08-01

The MediaTek Wi-Fi driver in Android before 2016-08-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29141147 and MediaTek internal bug ALPS02751738.

CVEs:CVE-2016-3852

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3841

Open SourceEPSS <= 49%HIGH2016-08-02

The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.

CVEs:CVE-2016-3841

Affected products

ProductStatusVendorPackageEcosystem
android affected google
linux_kernel affected linux
Upstream advisory

CVE-2016-2504

Open SourceEPSS <= 49%HIGH2016-08-02

The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28026365 and Qualcomm internal bug CR1002974.

CVEs:CVE-2016-2504

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2014-9868

Open SourceEPSS <= 49%HIGH2016-08-01

drivers/media/platform/msm/camera_v2/sensor/csiphy/msm_csiphy.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via an application that provides a crafted mask value, aka Andro...

CVEs:CVE-2014-9868

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3824

Open SourceEPSS <= 49%HIGH2016-08-02

omx/OMXNodeInstance.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not validate the buffer port, which allows attackers to gain privileges via a crafted applicati...

CVEs:CVE-2016-3824

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3850

Open SourceEPSS <= 49%CRITICAL2016-08-01

Integer overflow in app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted header field in a boot image, aka Android internal bug 27917291 and...

CVEs:CVE-2016-3850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3823

Open SourceEPSS <= 49%HIGH2016-08-02

The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a craft...

CVEs:CVE-2016-3823

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3825

Open SourceEPSS <= 49%HIGH2016-08-02

mm-video-v4l2/vidc/venc/src/omx_video_base.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allocates an incorrect amount of memory, which allows attackers to gain privileges via a crafted application, aka...

CVEs:CVE-2016-3825

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3826

Open SourceEPSS <= 49%HIGH2016-08-02

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not validate the reply size for an AudioFlinger effect command, which allows attackers to gain privileg...

CVEs:CVE-2016-3826

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3847

Open SourceEPSS <= 49%HIGH2016-08-02

The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28871433.

CVEs:CVE-2016-3847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3849

Open SourceEPSS <= 49%HIGH2016-08-02

The ION driver in Android before 2016-08-05 on Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28939740.

CVEs:CVE-2016-3849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3853

Open SourceEPSS <= 49%MEDIUM2016-08-01

Google Play services in Android before 2016-08-05 on Nexus devices allow local users to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26803208.

CVEs:CVE-2016-3853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.