|
265571
|
5.5 |
MEDIUM
Local
|
google
|
android
|
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive info…
|
CWE-200
Information Exposure
|
CVE-2016-2459
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265572
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive …
|
CWE-200
Information Exposure
|
CVE-2016-2458
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265573
|
5.5 |
MEDIUM
Local
|
google
|
android
|
server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended restrictions on Wi-Fi configuration changes…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2457
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265574
|
7.0 |
HIGH
Local
|
google
|
android
|
The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27275187.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2456
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265575
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
|
CWE-20
Improper Input Validation
|
CVE-2016-2454
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265576
|
7.0 |
HIGH
Local
|
google
|
android_one
|
The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27549705.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2453
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265577
|
7.8 |
HIGH
Local
|
google
|
android
|
codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate buffer sizes, which allo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2452
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265578
|
7.8 |
HIGH
Local
|
google
|
android
|
codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate VPX output buffer sizes, w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2451
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265579
|
7.8 |
HIGH
Local
|
google
|
android
|
codecs/on2/enc/SoftVPXEncoder.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate OMX buffer sizes, w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2450
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265580
|
7.8 |
HIGH
Local
|
google
|
android
|
services/camera/libcameraservice/device3/Camera3Device.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate template IDs…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2449
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|