Google

Android

8041 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.61%
  • Veröffentlicht 30.08.2016 17:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and ot...

  • EPSS 0.03%
  • Veröffentlicht 07.08.2016 21:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypas...

  • EPSS 0.09%
  • Veröffentlicht 07.08.2016 21:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.

Exploit
  • EPSS 51.99%
  • Veröffentlicht 06.08.2016 20:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

  • EPSS 0.03%
  • Veröffentlicht 06.08.2016 20:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.

  • EPSS 0.09%
  • Veröffentlicht 06.08.2016 10:59:57
  • Zuletzt bearbeitet 06.05.2026 22:30:45

netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR959631.

  • EPSS 0.08%
  • Veröffentlicht 06.08.2016 10:59:56
  • Zuletzt bearbeitet 06.05.2026 22:30:45

drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other ...

  • EPSS 0.08%
  • Veröffentlicht 06.08.2016 10:59:55
  • Zuletzt bearbeitet 06.05.2026 22:30:45

drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impac...

  • EPSS 0.06%
  • Veröffentlicht 06.08.2016 10:59:54
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information ...

  • EPSS 0.08%
  • Veröffentlicht 06.08.2016 10:59:53
  • Zuletzt bearbeitet 06.05.2026 22:30:45

drivers/video/msm/mdss/mdss_mdp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not verify that a mapping exists before proceeding with an unmap operation, which allows attackers to gain privileges via a crafted...