CVE-2016-4477
- EPSS 0.13%
- Veröffentlicht 09.05.2016 10:59:42
- Zuletzt bearbeitet 12.04.2025 10:46:40
wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafte...
CVE-2016-2462
- EPSS 0.06%
- Veröffentlicht 09.05.2016 10:59:40
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173.
CVE-2016-2461
- EPSS 0.09%
- Veröffentlicht 09.05.2016 10:59:39
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bugs 27324690 and 276966...
CVE-2016-2460
- EPSS 0.07%
- Veröffentlicht 09.05.2016 10:59:38
- Zuletzt bearbeitet 12.04.2025 10:46:40
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGrap...
CVE-2016-2459
- EPSS 0.07%
- Veröffentlicht 09.05.2016 10:59:37
- Zuletzt bearbeitet 12.04.2025 10:46:40
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGrap...
CVE-2016-2458
- EPSS 0.13%
- Veröffentlicht 09.05.2016 10:59:36
- Zuletzt bearbeitet 12.04.2025 10:46:40
The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive information via a crafted application, related to C...
CVE-2016-2457
- EPSS 0.03%
- Veröffentlicht 09.05.2016 10:59:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended restrictions on Wi-Fi configuration changes by leveraging guest access, aka internal bug 27411...
- EPSS 0.06%
- Veröffentlicht 09.05.2016 10:59:33
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27275187.
CVE-2016-2454
- EPSS 0.28%
- Veröffentlicht 09.05.2016 10:59:32
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
CVE-2016-2452
- EPSS 0.07%
- Veröffentlicht 09.05.2016 10:59:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate buffer sizes, which allows attackers to gain privileges via a crafted appli...