Show filters
375 Total Results
Displaying 251-260 of 375
Sort by:
Attacker Value
Unknown
CVE-2016-3833
Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka internal bug 29189712.
0
Attacker Value
Unknown
CVE-2016-3836
Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka internal bug 28592402.
0
Attacker Value
Unknown
CVE-2016-3823
Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a crafted application, aka internal bug 28815329.
0
Attacker Value
Unknown
CVE-2016-3834
Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, aka internal bug 28466701.
0
Attacker Value
Unknown
CVE-2016-3831
Disclosure Date: August 05, 2016 (last updated November 25, 2024)
The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ time value of 2038-01-19 or later that is mishandled by the system clock, aka internal bug 29083635, related to a "Year 2038 problem."
0
Attacker Value
Unknown
CVE-2016-3825
Disclosure Date: August 05, 2016 (last updated November 25, 2024)
mm-video-v4l2/vidc/venc/src/omx_video_base.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allocates an incorrect amount of memory, which allows attackers to gain privileges via a crafted application, aka internal bug 28816964.
0
Attacker Value
Unknown
CVE-2016-3766
Disclosure Date: July 11, 2016 (last updated November 25, 2024)
MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not check whether memory allocation succeeds, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28471206.
0
Attacker Value
Unknown
CVE-2016-3763
Disclosure Date: July 11, 2016 (last updated November 25, 2024)
net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating a server with a PAC script, aka internal bug 27593919.
0
Attacker Value
Unknown
CVE-2016-3760
Disclosure Date: July 11, 2016 (last updated November 25, 2024)
Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairing that remains present during a session of the primary user, aka internal bug 27410683.
0
Attacker Value
Unknown
CVE-2016-3761
Disclosure Date: July 11, 2016 (last updated November 25, 2024)
NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background application, aka internal bug 28300969.
0