|
265711
|
9.8 |
CRITICAL
Network
|
google
|
android
|
Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3840
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265712
|
5.5 |
MEDIUM
Local
|
google
|
android
|
Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a craf…
|
CWE-284
Improper Access Control
|
CVE-2016-3839
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265713
|
5.5 |
MEDIUM
Local
|
google
|
android
|
Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 287…
|
CWE-284
Improper Access Control
|
CVE-2016-3838
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265714
|
5.5 |
MEDIUM
Local
|
google
|
android
|
service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted…
|
CWE-200
Information Exposure
|
CVE-2016-3837
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265715
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of …
|
CWE-200
Information Exposure
|
CVE-2016-3836
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265716
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, …
|
CWE-200
Information Exposure
|
CVE-2016-3835
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265717
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information …
|
CWE-200
Information Exposure
|
CVE-2016-3834
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265718
|
7.8 |
HIGH
Local
|
google
|
android
|
The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3833
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265719
|
7.8 |
HIGH
Local
|
google
|
android
|
The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows att…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3832
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265720
|
7.5 |
HIGH
Network
|
google
|
android
|
The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ t…
|
CWE-20
Improper Input Validation
|
CVE-2016-3831
|
2024-11-21 11:50 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|