CVE-2016-2430
- EPSS 0.04%
- Veröffentlicht 09.05.2016 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to gain privileges via an application containing a crafted symbol name, aka internal bug 27299236.
- EPSS 1.22%
- Veröffentlicht 09.05.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
libFLAC/stream_decoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not prevent free operations on uninitialized memory, which allows remote attackers to execute arbitrary code o...
- EPSS 1.22%
- Veröffentlicht 09.05.2016 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
libAACdec/src/aacdec_drc.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly limit the number of threads, which allows remote attackers to execute arbitrary code or cause...
CVE-2016-2060
- EPSS 0.04%
- Veröffentlicht 09.05.2016 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attacke...
- EPSS 0.04%
- Veröffentlicht 05.05.2016 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does no...
- EPSS 36.96%
- Veröffentlicht 05.05.2016 01:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "ne...
CVE-2016-2107
- EPSS 79.96%
- Veröffentlicht 05.05.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against...
CVE-2016-0774
- EPSS 0.02%
- Veröffentlicht 27.04.2016 17:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do ...
CVE-2016-2427
- EPSS 0.08%
- Veröffentlicht 18.04.2016 00:59:33
- Zuletzt bearbeitet 12.05.2025 17:37:16
The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key...
CVE-2016-2426
- EPSS 0.07%
- Veröffentlicht 18.04.2016 00:59:32
- Zuletzt bearbeitet 12.04.2025 10:46:40
server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a GET_ACCOUNTS permission, which allows attackers to obtain sensitive info...