|
270631
|
- |
|
google
|
android
|
The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restricti…
|
CWE-284
Improper Access Control
|
CVE-2015-3833
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270632
|
- |
|
google
|
android
|
Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via invalid size values of NAL units in MP4 data, aka…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3832
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270633
|
- |
|
google
|
android
|
Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnection.cpp in the mediaserver service in Android before 5.1.1 LMY48I allows attackers to execute arbitr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3831
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270634
|
- |
|
google
|
android
|
Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code or cause a denial …
|
CWE-189
Numeric Errors
|
CVE-2015-3829
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270635
|
- |
|
google
|
android
|
The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (…
|
CWE-119 CWE-189
Incorrect Access of Indexable Resource ('Range Error') Numeric Errors
|
CVE-2015-3828
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270636
|
- |
|
google
|
android
|
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship between chunk sizes and skip sizes, which allows remo…
|
CWE-119 CWE-189
Incorrect Access of Indexable Resource ('Range Error') Numeric Errors
|
CVE-2015-3827
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270637
|
- |
|
google
|
android
|
The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (…
|
CWE-119 CWE-189
Incorrect Access of Indexable Resource ('Range Error') Numeric Errors
|
CVE-2015-3826
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270638
|
- |
|
google
|
android
|
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3824
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270639
|
- |
|
apple
|
iphone_os safari
|
The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vecto…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3801
|
2024-11-21 11:29 |
2015-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270640
|
- |
|
qlik
|
qlikview
|
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML d…
|
NVD-CWE-Other
|
CVE-2015-3623
|
2024-11-21 11:29 |
2015-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|