|
268881
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10341
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268882
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10340
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268883
|
7.1 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.
|
CWE-200
Information Exposure
|
CVE-2016-10339
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268884
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
|
CWE-20
Improper Input Validation
|
CVE-2016-10338
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268885
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
|
CWE-20
Improper Input Validation
|
CVE-2016-10337
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268886
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
|
CWE-254
7PK - Security Features
|
CVE-2016-10336
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268887
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
|
CWE-284
Improper Access Control
|
CVE-2016-10335
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268888
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
|
CWE-284
Improper Access Control
|
CVE-2016-10334
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268889
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
|
CWE-284
Improper Access Control
|
CVE-2016-10333
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268890
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
|
CWE-254
7PK - Security Features
|
CVE-2016-10332
|
2024-11-21 11:43 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|