CVE-2016-1948
- EPSS 0.22%
- Veröffentlicht 31.01.2016 18:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.
CVE-2016-1943
- EPSS 0.56%
- Veröffentlicht 31.01.2016 18:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
CVE-2016-1940
- EPSS 0.32%
- Veröffentlicht 31.01.2016 18:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.
CVE-2015-6647
- EPSS 0.17%
- Veröffentlicht 06.01.2016 19:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.
CVE-2015-6646
- EPSS 0.1%
- Veröffentlicht 06.01.2016 19:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manage...
CVE-2015-6645
- EPSS 0.05%
- Veröffentlicht 06.01.2016 19:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a crafted application, aka internal bug 23591205.
CVE-2015-6644
- EPSS 0.18%
- Veröffentlicht 06.01.2016 19:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
CVE-2015-6643
- EPSS 0.01%
- Veröffentlicht 06.01.2016 19:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.
CVE-2015-6642
- EPSS 0.14%
- Veröffentlicht 06.01.2016 19:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or Signatur...
CVE-2015-6641
- EPSS 0.07%
- Veröffentlicht 06.01.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.