Latest CVE Feed
-
7.1
HIGHCVE-2016-3829
The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29023649.... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-3828
decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-3827
codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 288169... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3826
services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not validate the reply size for an AudioFlinger effect command, which allows attackers to gain privileges ... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3825
mm-video-v4l2/vidc/venc/src/omx_video_base.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allocates an incorrect amount of memory, which allows attackers to gain privileges via a crafted application, aka in... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3824
omx/OMXNodeInstance.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not validate the buffer port, which allows attackers to gain privileges via a crafted application,... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3823
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a crafted ... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3822
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access)... Read more
- EPSS Score: %0.46
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-3821
libmedia in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 has certain incorrect declarations, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer d... Read more
Affected Products : android- EPSS Score: %1.40
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-3820
The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 mishandles slice numbers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28673410.... Read more
Affected Products : android- EPSS Score: %1.49
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-3819
Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to execute arbitrary code or cause a denial... Read more
Affected Products : android- EPSS Score: %1.49
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-2504
The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28026365 and Qualcomm internal bug CR1002974.... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2497
services/core/java/com/android/server/pm/PackageManagerService.java in the framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to increase intent-filter priority via a crafted appl... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-9902
Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management ... Read more
Affected Products : android- EPSS Score: %3.88
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-9901
The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cause a denial of service (device hang or reboot) via crafted frames, aka Android internal bug 28670333 and Q... Read more
Affected Products : android- EPSS Score: %0.51
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-6186
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to injec... Read more
- EPSS Score: %13.10
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-5392
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the wa... Read more
- EPSS Score: %0.34
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4999
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup fil... Read more
- EPSS Score: %3.51
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1278
Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privileges by leveraging use of the "req... Read more
- EPSS Score: %0.06
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-1276
Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D23, 12.3X48 before 12.3X48-D25, and 15.1X49 before 15.1X49-D40 on a High-End SRX-Series chassis system with one or more Application Layer Gateways (ALGs) enabled allow remote attackers to cause ... Read more
- EPSS Score: %0.77
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025