|
271911
|
- |
|
google
|
android
|
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3823
|
2024-11-21 11:29 |
2015-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271912
|
- |
|
google
|
android
|
libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.
|
CWE-20
Improper Input Validation
|
CVE-2015-3876
|
2024-11-21 11:29 |
2015-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271913
|
- |
|
google
|
android
|
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code vi…
|
CWE-189
Numeric Errors
|
CVE-2015-3864
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271914
|
- |
|
google
|
android
|
Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an appl…
|
CWE-189
Numeric Errors
|
CVE-2015-3863
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271915
|
- |
|
google
|
android
|
Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allow remote attackers to cause a denia…
|
CWE-189
Numeric Errors
|
CVE-2015-3861
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271916
|
- |
|
google
|
android
|
packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows phys…
|
CWE-284
Improper Access Control
|
CVE-2015-3860
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271917
|
- |
|
google
|
android
|
The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3858
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271918
|
- |
|
google
|
android
|
The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3849
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271919
|
- |
|
google
|
android
|
The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3845
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271920
|
- |
|
google
|
android
|
The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 LMY48I allows attackers to trigger incorrect proce…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3844
|
2024-11-21 11:29 |
2015-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|