Latest CVE Feed
-
7.8
HIGHCVE-2016-3847
The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28871433.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3846
The Serial Peripheral Interface driver in Android before 2016-08-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28817378.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3845
The video driver in the kernel in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28399876.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3844
mediaserver in Android before 2016-08-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28299517.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3843
Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka A... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3842
The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28377352 and Qualcomm internal bug CR1002974.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-3840
Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.... Read more
Affected Products : android- EPSS Score: %2.30
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3839
Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a crafted application that sends a signal to a Bluetooth proce... Read more
Affected Products : android- EPSS Score: %0.13
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3838
Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3837
service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application that provides a MAC address with too few ch... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3836
The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka in... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3835
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to obtain sensitive information v... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3834
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, ak... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3833
The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypass intended access restrictions via a crafted applicatio... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2016-3832
The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows attackers to bypass an unspecified protection mechanism via... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3831
The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ time value of 2038-01-19 or later that is mishandled by t... Read more
Affected Products : android- EPSS Score: %0.50
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-3830
codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device hang or reboot) via crafted ADTS data, ... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-3829
The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29023649.... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-3828
decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-3827
codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 288169... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025