CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2016-3838

    Last Modified: 12 Apr 2025

    Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.

    Published: 5 Aug 2016
    7
    High

    CVE-2016-3846

    Last Modified: 12 Apr 2025

    The Serial Peripheral Interface driver in Android before 2016-08-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28817378.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3825

    Last Modified: 12 Apr 2025

    mm-video-v4l2/vidc/venc/src/omx_video_base.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allocates an incorrect amount of memory, which allows attackers to gain privileges via a crafted application, aka internal bug 28816964.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3832

    Last Modified: 12 Apr 2025

    The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows attackers to bypass an unspecified protection mechanism via a crafted application, aka internal bug 28795098.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3839

    Last Modified: 12 Apr 2025

    Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a crafted application that sends a signal to a Bluetooth process, aka internal bug 28885210.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3847

    Last Modified: 12 Apr 2025

    The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28871433.

    Published: 5 Aug 2016
    7.5
    High

    CVE-2014-9901

    Last Modified: 12 Apr 2025

    The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cause a denial of service (device hang or reboot) via crafted frames, aka Android internal bug 28670333 and Qualcomm internal bug CR548711.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2014-9902

    Last Modified: 12 Apr 2025

    Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows remote attackers to execute arbitrary code via a crafted Information Element (IE) in an 802.11 management frame, aka Android internal bug 28668638 and Qualcomm internal bugs CR553937 and CR553941.

    Published: 5 Aug 2016
    7.3
    High

    CVE-2016-2497

    Last Modified: 12 Apr 2025

    services/core/java/com/android/server/pm/PackageManagerService.java in the framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to increase intent-filter priority via a crafted application, aka internal bug 27450489.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-2504

    Last Modified: 12 Apr 2025

    The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28026365 and Qualcomm internal bug CR1002974.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3845

    Last Modified: 12 Apr 2025

    The video driver in the kernel in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28399876.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-3819

    Last Modified: 12 Apr 2025

    Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28533562.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-3820

    Last Modified: 12 Apr 2025

    The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 mishandles slice numbers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28673410.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-3821

    Last Modified: 12 Apr 2025

    libmedia in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 has certain incorrect declarations, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference or memory corruption) via a crafted media file, aka internal bug 28166152.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3822

    Last Modified: 12 Apr 2025

    exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3823

    Last Modified: 12 Apr 2025

    The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a crafted application, aka internal bug 28815329.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3827

    Last Modified: 12 Apr 2025

    codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28816956.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3828

    Last Modified: 12 Apr 2025

    decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3829

    Last Modified: 12 Apr 2025

    The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29023649.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3830

    Last Modified: 12 Apr 2025

    codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device hang or reboot) via crafted ADTS data, aka internal bug 29153599.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3833

    Last Modified: 12 Apr 2025

    The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka internal bug 29189712.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3834

    Last Modified: 12 Apr 2025

    The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, aka internal bug 28466701.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3835

    Last Modified: 12 Apr 2025

    The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 28920116.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3836

    Last Modified: 12 Apr 2025

    The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka internal bug 28592402.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3837

    Last Modified: 12 Apr 2025

    service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application that provides a MAC address with too few characters, aka internal bug 28164077.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-3840

    Last Modified: 12 Apr 2025

    Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3842

    Last Modified: 12 Apr 2025

    The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28377352 and Qualcomm internal bug CR1002974.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3843

    Last Modified: 12 Apr 2025

    Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka Android internal bugs 28086229 and 29119870 and Qualcomm internal bug CR1011071.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3844

    Last Modified: 12 Apr 2025

    mediaserver in Android before 2016-08-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28299517.

    Published: 5 Aug 2016
    7
    High

    CVE-2016-3848

    Last Modified: 12 Apr 2025

    The NVIDIA media driver in Android before 2016-08-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28919417.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3849

    Last Modified: 12 Apr 2025

    The ION driver in Android before 2016-08-05 on Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28939740.

    Published: 5 Aug 2016
    7.3
    High

    CVE-2016-3850

    Last Modified: 12 Apr 2025

    Integer overflow in app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted header field in a boot image, aka Android internal bug 27917291 and Qualcomm internal bug CR945164.

    Published: 5 Aug 2016
    8.1
    High

    CVE-2016-3851

    Last Modified: 12 Apr 2025

    The LG Electronics bootloader Android before 2016-08-05 on Nexus 5X devices allows attackers to gain privileges by leveraging access to a privileged process, aka internal bug 29189941.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3852

    Last Modified: 12 Apr 2025

    The MediaTek Wi-Fi driver in Android before 2016-08-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29141147 and MediaTek internal bug ALPS02751738.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3853

    Last Modified: 12 Apr 2025

    Google Play services in Android before 2016-08-05 on Nexus devices allow local users to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26803208.

    Published: 5 Aug 2016
    5.9
    Medium

    CVE-2016-1276

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D23, 12.3X48 before 12.3X48-D25, and 15.1X49 before 15.1X49-D40 on a High-End SRX-Series chassis system with one or more Application Layer Gateways (ALGs) enabled allow remote attackers to cause a denial of service (CPU consumption, fab link failure, or flip-flop failovers) via vectors related to in-transit traffic matching ALG rules.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-1278

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 12.1X46-D50 on SRX Series devices reverts to "safe mode" authentication and allows root CLI logins without a password after a failed upgrade to 12.1X46, which might allow local users to gain privileges by leveraging use of the "request system software" command with the "partition" option.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-3640

    Last Modified: 12 Apr 2025

    The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obtain sensitive password information via vectors related to passwords in Web Dispatcher trace files, aka SAP Security Note 2148905.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-6150

    Last Modified: 12 Apr 2025

    The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly have unspecified other impact via unknown vectors, aka SAP Security Note 2233550.

    Published: 5 Aug 2016
    5.3
    Medium

    CVE-2016-6145

    Last Modified: 12 Apr 2025

    The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_connect option is not supported or is configured as "False," which allows remote attackers to enumerate database users via a series of login attempts, aka SAP Security Note 2216869.

    Published: 5 Aug 2016
    5.4
    Medium

    CVE-2016-3196

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an image uploaded in the report section.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-1513

    Last Modified: 12 Apr 2025

    The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-6139

    Last Modified: 12 Apr 2025

    SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-6140

    Last Modified: 12 Apr 2025

    SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-6138

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.

    Published: 5 Aug 2016
    8.1
    High

    CVE-2016-6144

    Last Modified: 12 Apr 2025

    The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is configured as "False," which makes it easier for remote attackers to bypass authentication via a brute force attack, aka SAP Security Note 2216869.

    Published: 5 Aug 2016
    9.8
    Critical

    CVE-2016-6147

    Last Modified: 12 Apr 2025

    An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226.

    Published: 5 Aug 2016
    7.5
    High

    CVE-2016-6148

    Last Modified: 12 Apr 2025

    SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors related to an IMPORT statement, aka SAP Security Note 2233136.

    Published: 5 Aug 2016
    5.5
    Medium

    CVE-2016-6149

    Last Modified: 12 Apr 2025

    SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941.

    Published: 5 Aug 2016
    8.8
    High

    CVE-2016-5261

    Last Modified: 12 Apr 2025

    Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 and Firefox ESR < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets that trigger incorrect buffer-resize operations during buffering.

    Published: 5 Aug 2016