Google Security Advisories · November 2016 — Google Security Advisories
75 advisories 73 CVEs 8 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2016-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 8 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2016-7255

Project ZeroExploitedCISA KEV listed2016-11-02

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CVEs:CVE-2016-7255

Upstream advisory

CVE-2016-7255

GoogleExploitedCISA KEV listedHIGH2016-11-02

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain ...

CVEs:CVE-2016-7255

Affected products

ProductStatusVendorPackageEcosystem
windows affected microsoft
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2016-7256

GoogleExploitedCISA KEV listedHIGH2016-11-09

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remot...

CVEs:CVE-2016-7256

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1511 affected microsoft
windows_10_1607 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_vista affected microsoft
Upstream advisory

CVE-2016-7256

Project ZeroExploitedCISA KEV listed2016-11-09

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Open Type Font Remote Code Execution Vulnerability."

CVEs:CVE-2016-7256

Upstream advisory

MGASA-2016-0403

Open SourceExploitedCISA KEV listedCRITICAL2016-11-27

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:5 chromium-browser-stable
Upstream advisory

openSUSE-SU-2016:2732-1

Open SourceExploitedCISA KEV listed2016-11-04

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

openSUSE-SU-2016:2733-1

Open SourceExploitedCISA KEV listed2016-11-04

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 chromium
Upstream advisory

CVE-2016-5198

GoogleExploitedCISA KEV listedCRITICAL2016-11-03

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to ...

CVEs:CVE-2016-5198

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
Upstream advisory

CVE-2016-6754

Open SourceWeaponized exploitHIGH2016-11-08

A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High...

CVEs:CVE-2016-6754

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6707

Open SourceWeaponized exploitHIGH2016-11-08

An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as ...

CVEs:CVE-2016-6707

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6717

Open SourceWeaponized exploitHIGH2016-11-08

An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the...

CVEs:CVE-2016-6717

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6723

Open SourceWeaponized exploitHIGH2016-11-08

A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a remote attacker to use a specially crafted file to cause a devic...

CVEs:CVE-2016-6723

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2026-39821

Open SourceActive exploitation (sightings)CRITICAL2016-11-05

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to pri...

CVEs:CVE-2026-39821

Affected products

ProductStatusVendorPackageEcosystem
golang.org/x/net/idna affected golang.org/x/net
golang.org/x/net/idna affected golang
idna affected golang.org/x/net
net affected golang
net affected golang
Upstream advisory

CVE-2014-9908

Open SourcePoC exploitHIGH2016-11-08

A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).

CVEs:CVE-2014-9908

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6718

Open SourcePoC exploitHIGH2016-11-08

An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11-01 could enable a local malicious application to retrieve sensitive information without user interaction. This issue is rated as Moderate because it is...

CVEs:CVE-2016-6718

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6727

Open SourceEPSS <= 49%HIGH2016-11-08

The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.

CVEs:CVE-2016-6727

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6725

Open SourceEPSS <= 49%HIGH2016-11-08

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote...

CVEs:CVE-2016-6725

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

RHSA-2016:2718

Open SourceEPSS <= 49%HIGH2016-11-14

Red Hat Security Advisory: chromium-browser security update

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser affected Red Hat:rhel_extras:6 chromium-browser
chromium-browser-debuginfo affected Red Hat:rhel_extras:6 chromium-browser-debuginfo
Upstream advisory

CVE-2016-5200

GoogleEPSS <= 49%HIGH2016-11-14

V8 in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android incorrectly applied type rules, which allowed a remote attacker to potentially exploit heap corruption via a craf...

CVEs:CVE-2016-5200

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-5199

GoogleEPSS <= 49%HIGH2016-11-14

An off by one error resulting in an allocation of zero size in FFmpeg in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially explo...

CVEs:CVE-2016-5199

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6699

Open SourceEPSS <= 49%HIGH2016-11-08

A remote code execution vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Cri...

CVEs:CVE-2016-6699

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6728

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibili...

CVEs:CVE-2016-6728

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5201

GoogleEPSS <= 49%MEDIUM2016-11-14

A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.

CVEs:CVE-2016-5201

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6702

Open SourceEPSS <= 49%HIGH2016-11-08

A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This i...

CVEs:CVE-2016-6702

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6703

Open SourceEPSS <= 49%HIGH2016-11-08

A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker using a specially crafted payload to execute arbitrary code in t...

CVEs:CVE-2016-6703

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6701

Open SourceEPSS <= 49%CRITICAL2016-11-08

A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibili...

CVEs:CVE-2016-6701

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6704

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the...

CVEs:CVE-2016-6704

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6700

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is...

CVEs:CVE-2016-6700

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6711

Open SourceEPSS <= 49%HIGH2016-11-08

A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. ...

CVEs:CVE-2016-6711

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-5202

GoogleEPSS <= 49%CRITICAL2016-11-14

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to acces...

CVEs:CVE-2016-5202

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2016-6726

Open SourceEPSS <= 49%HIGH2016-11-08

Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.

CVEs:CVE-2016-6726

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6705

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in Mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a priv...

CVEs:CVE-2016-6705

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6706

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High becau...

CVEs:CVE-2016-6706

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6713

Open SourceEPSS <= 49%HIGH2016-11-08

A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibi...

CVEs:CVE-2016-6713

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6738

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Qualcomm crypto engine driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it firs...

CVEs:CVE-2016-6738

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6740

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requi...

CVEs:CVE-2016-6740

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6741

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requi...

CVEs:CVE-2016-6741

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6742

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first...

CVEs:CVE-2016-6742

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6744

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first...

CVEs:CVE-2016-6744

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6745

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first...

CVEs:CVE-2016-6745

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6712

Open SourceEPSS <= 49%HIGH2016-11-08

A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. ...

CVEs:CVE-2016-6712

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6734

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility ...

CVEs:CVE-2016-6734

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6735

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility ...

CVEs:CVE-2016-6735

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6720

Open SourceEPSS <= 49%HIGH2016-11-08

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data out...

CVEs:CVE-2016-6720

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6730

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility ...

CVEs:CVE-2016-6730

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6731

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility ...

CVEs:CVE-2016-6731

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6732

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility ...

CVEs:CVE-2016-6732

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6733

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility ...

CVEs:CVE-2016-6733

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6736

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility ...

CVEs:CVE-2016-6736

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6737

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibili...

CVEs:CVE-2016-6737

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6739

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requi...

CVEs:CVE-2016-6739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6743

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first...

CVEs:CVE-2016-6743

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3904

Open SourceEPSS <= 49%HIGH2016-11-07

An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires...

CVEs:CVE-2016-3904

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6729

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Qualcomm bootloader in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibilit...

CVEs:CVE-2016-6729

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6747

Open SourceEPSS <= 49%HIGH2016-11-08

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. And...

CVEs:CVE-2016-6747

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6709

Open SourceEPSS <= 49%HIGH2016-11-08

An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an...

CVEs:CVE-2016-6709

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6714

Open SourceEPSS <= 49%HIGH2016-11-08

A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibi...

CVEs:CVE-2016-6714

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6753

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels...

CVEs:CVE-2016-6753

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6722

Open SourceEPSS <= 49%HIGH2016-11-08

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data out...

CVEs:CVE-2016-6722

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6710

Open SourceEPSS <= 49%HIGH2016-11-08

An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that i...

CVEs:CVE-2016-6710

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3906

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-3906

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6698

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-6698

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6750

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-6750

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6721

Open SourceEPSS <= 49%HIGH2016-11-08

An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it cou...

CVEs:CVE-2016-6721

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6724

Open SourceEPSS <= 49%HIGH2016-11-08

A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to cause the device to conti...

CVEs:CVE-2016-6724

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-3907

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-3907

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6748

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-6748

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6749

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-6749

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6751

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-6751

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6752

Open SourceEPSS <= 49%MEDIUM2016-11-08

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its pe...

CVEs:CVE-2016-6752

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6746

Open SourceEPSS <= 49%HIGH2016-11-08

An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sen...

CVEs:CVE-2016-6746

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6715

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio without the us...

CVEs:CVE-2016-6715

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6716

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent. This issue is rated as Moderate becaus...

CVEs:CVE-2016-6716

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6719

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to pair with any Bluetoo...

CVEs:CVE-2016-6719

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2016-6708

Open SourceEPSS <= 49%HIGH2016-11-08

An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypass of user in...

CVEs:CVE-2016-6708

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.