CVE-2016-5344
- EPSS 0.65%
- Veröffentlicht 30.08.2016 17:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified o...
CVE-2016-5342
- EPSS 0.61%
- Veröffentlicht 30.08.2016 17:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and ot...
CVE-2016-5340
- EPSS 0.03%
- Veröffentlicht 07.08.2016 21:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypas...
CVE-2015-3854
- EPSS 0.09%
- Veröffentlicht 07.08.2016 21:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.
CVE-2016-5696
- EPSS 33.3%
- Veröffentlicht 06.08.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
CVE-2016-3841
- EPSS 0.03%
- Veröffentlicht 06.08.2016 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.
CVE-2016-3856
- EPSS 0.09%
- Veröffentlicht 06.08.2016 10:59:57
- Zuletzt bearbeitet 12.04.2025 10:46:40
netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR959631.
CVE-2016-3855
- EPSS 0.08%
- Veröffentlicht 06.08.2016 10:59:56
- Zuletzt bearbeitet 12.04.2025 10:46:40
drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other ...
CVE-2016-3854
- EPSS 0.08%
- Veröffentlicht 06.08.2016 10:59:55
- Zuletzt bearbeitet 12.04.2025 10:46:40
drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impac...
CVE-2015-8944
- EPSS 0.06%
- Veröffentlicht 06.08.2016 10:59:54
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information ...