Latest CVE Feed
-
7.3
HIGHCVE-2016-3850
Integer overflow in app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted header field in a boot image, aka Android internal bug 27917291 and Qu... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3849
The ION driver in Android before 2016-08-05 on Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28939740.... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3848
The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28919417.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3847
The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28871433.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3846
The Serial Peripheral Interface driver in Android before 2016-08-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28817378.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3845
The video driver in the kernel in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28399876.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3844
mediaserver in Android before 2016-08-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28299517.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3843
Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka A... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3842
The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28377352 and Qualcomm internal bug CR1002974.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-3840
Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.... Read more
Affected Products : android- EPSS Score: %2.30
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3839
Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a crafted application that sends a signal to a Bluetooth proce... Read more
Affected Products : android- EPSS Score: %0.13
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3838
Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3837
service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application that provides a MAC address with too few ch... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3836
The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka in... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3835
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to obtain sensitive information v... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3834
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, ak... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3833
The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypass intended access restrictions via a crafted applicatio... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2016-3832
The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows attackers to bypass an unspecified protection mechanism via... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3831
The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device crash) via a NITZ time value of 2038-01-19 or later that is mishandled by t... Read more
Affected Products : android- EPSS Score: %0.50
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-3830
codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device hang or reboot) via crafted ADTS data, ... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025