Show filters
218 Total Results
Displaying 121-130 of 218
Sort by:
Attacker Value
Unknown

CVE-2016-3830

Disclosure Date: August 05, 2016 (last updated November 25, 2024)
codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device hang or reboot) via crafted ADTS data, aka internal bug 29153599.
0
Attacker Value
Unknown

CVE-2016-3832

Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows attackers to bypass an unspecified protection mechanism via a crafted application, aka internal bug 28795098.
0
Attacker Value
Unknown

CVE-2016-3823

Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a crafted application, aka internal bug 28815329.
0
Attacker Value
Unknown

CVE-2016-3834

Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, aka internal bug 28466701.
0
Attacker Value
Unknown

CVE-2016-3831

Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ time value of 2038-01-19 or later that is mishandled by the system clock, aka internal bug 29083635, related to a "Year 2038 problem."
0
Attacker Value
Unknown

CVE-2016-3818

Disclosure Date: July 11, 2016 (last updated November 25, 2024)
libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28740702.
0
Attacker Value
Unknown

CVE-2016-3766

Disclosure Date: July 11, 2016 (last updated November 25, 2024)
MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not check whether memory allocation succeeds, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28471206.
0
Attacker Value
Unknown

CVE-2016-3763

Disclosure Date: July 11, 2016 (last updated November 25, 2024)
net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating a server with a PAC script, aka internal bug 27593919.
0
Attacker Value
Unknown

CVE-2016-3761

Disclosure Date: July 11, 2016 (last updated November 25, 2024)
NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background application, aka internal bug 28300969.
0
Attacker Value
Unknown

CVE-2016-3764

Disclosure Date: July 11, 2016 (last updated November 25, 2024)
media/libmediaplayerservice/MetadataRetrieverClient.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive pointer information via a crafted application, aka internal bug 28377502.
0