Google

Android

7930 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 07.08.2016 21:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypas...

  • EPSS 0.12%
  • Veröffentlicht 07.08.2016 21:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.

Exploit
  • EPSS 34.41%
  • Veröffentlicht 06.08.2016 20:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

  • EPSS 0.03%
  • Veröffentlicht 06.08.2016 20:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.

  • EPSS 0.09%
  • Veröffentlicht 06.08.2016 10:59:57
  • Zuletzt bearbeitet 12.04.2025 10:46:40

netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR959631.

  • EPSS 0.08%
  • Veröffentlicht 06.08.2016 10:59:56
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other ...

  • EPSS 0.08%
  • Veröffentlicht 06.08.2016 10:59:55
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impac...

  • EPSS 0.06%
  • Veröffentlicht 06.08.2016 10:59:54
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information ...

  • EPSS 0.08%
  • Veröffentlicht 06.08.2016 10:59:53
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/video/msm/mdss/mdss_mdp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not verify that a mapping exists before proceeding with an unmap operation, which allows attackers to gain privileges via a crafted...

  • EPSS 0.06%
  • Veröffentlicht 06.08.2016 10:59:52
  • Zuletzt bearbeitet 12.04.2025 10:46:40

drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices does not validate the stream state, which allows attackers to gain privileges via a crafted application, aka Android i...