CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2014-9786

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28557260 and Qualcomm internal bug CR545979.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2014-9790

    Last Modified: 12 Apr 2025

    drivers/mmc/core/debugfs.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate pointers used in read and write operations, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769136 and Qualcomm internal bug CR545716.

    Published: 11 Jul 2016
    Unknown

    CVE-2014-9791

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0196. Reason: This candidate is a reservation duplicate of CVE-2014-0196. Notes: All CVE users should reference CVE-2014-0196 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Jul 2016
    7.8
    High

    CVE-2014-9792

    Last Modified: 12 Apr 2025

    arch/arm/mach-msm/ipc_router.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices uses an incorrect integer data type, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769399 and Qualcomm internal bug CR550606.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2014-9793

    Last Modified: 12 Apr 2025

    platform/msm_shared/mmc.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices mishandles the power-on write-protect feature, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28821253 and Qualcomm internal bug CR580567.

    Published: 11 Jul 2016
    Unknown

    CVE-2014-9797

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0974. Reason: This candidate is a reservation duplicate of CVE-2014-0974. Notes: All CVE users should reference CVE-2014-0974 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Jul 2016
    5.5
    Medium

    CVE-2014-9798

    Last Modified: 12 Apr 2025

    platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a denial of service (OS outage) via a crafted application, aka Android internal bug 28821448 and Qualcomm internal bug CR681965.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2014-9799

    Last Modified: 12 Apr 2025

    The makefile in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices omits the -fno-strict-overflow option to gcc, which might allow attackers to gain privileges via a crafted application that leverages incorrect compiler optimization of an integer-overflow protection mechanism, aka Android internal bug 28821731 and Qualcomm internal bug CR691916.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2014-9800

    Last Modified: 12 Apr 2025

    Integer overflow in lib/heap/heap.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28822150 and Qualcomm internal bug CR692478.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2014-9801

    Last Modified: 12 Apr 2025

    Multiple integer overflows in lib/libfdt/fdt_rw.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28822060 and Qualcomm internal bug CR705078.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2014-9802

    Last Modified: 12 Apr 2025

    Multiple integer overflows in lib/libfdt/fdt.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28821965 and Qualcomm internal bug CR705108.

    Published: 11 Jul 2016
    5.5
    Medium

    CVE-2015-8893

    Last Modified: 12 Apr 2025

    app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to cause a denial of service (OS outage or buffer over-read) via a crafted application, aka Android internal bug 28822690 and Qualcomm internal bug CR822275.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2015-8888

    Last Modified: 12 Apr 2025

    Integer overflow in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows attackers to bypass intended access restrictions via a crafted block count and block size of a sparse header, aka Android internal bug 28822465 and Qualcomm internal bug CR813933.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2015-8889

    Last Modified: 12 Apr 2025

    The aboot implementation in the Qualcomm components in Android before 2016-07-05 on Nexus 6P devices omits the recovery PIN feature, which has unspecified impact and attack vectors, aka Android internal bug 28822677 and Qualcomm internal bug CR804067.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2015-8890

    Last Modified: 12 Apr 2025

    platform/msm_shared/partition_parser.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate certain GUID Partition Table (GPT) data, which allows attackers to bypass intended access restrictions via a crafted MultiMediaCard (MMC), aka Android internal bug 28822878 and Qualcomm internal bug CR823461.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2015-8891

    Last Modified: 12 Apr 2025

    Multiple integer overflows in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to bypass intended access restrictions via a crafted image, aka Android internal bug 28842418 and Qualcomm internal bug CR813930.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2015-8892

    Last Modified: 12 Apr 2025

    platform/msm_shared/boot_verifier.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to bypass intended access restrictions via a digest with trailing data, aka Android internal bug 28822807 and Qualcomm internal bug CR902998.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-2067

    Last Modified: 12 Apr 2025

    drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows attackers to gain privileges by leveraging accidental read-write mappings, aka Qualcomm internal bug CR988993.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-2068

    Last Modified: 12 Apr 2025

    The MSM QDSP6 audio driver (aka sound driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (integer overflow, and buffer overflow or buffer over-read) via a crafted application that performs a (1) AUDIO_EFFECTS_WRITE or (2) AUDIO_EFFECTS_READ operation, aka Qualcomm internal bug CR1006609.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-2502

    Last Modified: 12 Apr 2025

    drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a large size in a GSER_IOCTL ioctl call, aka Android internal bug 27657963 and Qualcomm internal bug CR997044.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-2503

    Last Modified: 12 Apr 2025

    The Qualcomm GPU driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28084795 and Qualcomm internal bug CR1006067.

    Published: 11 Jul 2016
    9.8
    Critical

    CVE-2016-2506

    Last Modified: 12 Apr 2025

    DRMExtractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate a certain offset value, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28175045.

    Published: 11 Jul 2016
    9.8
    Critical

    CVE-2016-3742

    Last Modified: 12 Apr 2025

    decoder/ih264d_process_intra_mb.c in mediaserver in Android 6.x before 2016-07-01 mishandles intra mode, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28165659.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3746

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27890802.

    Published: 11 Jul 2016
    8.4
    High

    CVE-2016-3748

    Last Modified: 12 Apr 2025

    The sockets subsystem in Android 6.x before 2016-07-01 allows attackers to bypass intended system-call restrictions via a crafted application that makes an ioctl call, aka internal bug 28171804.

    Published: 11 Jul 2016
    8.4
    High

    CVE-2016-3749

    Last Modified: 12 Apr 2025

    server/LockSettingsService.java in LockSettingsService in Android 6.x before 2016-07-01 allows attackers to modify the screen-lock password or pattern via a crafted application, aka internal bug 28163930.

    Published: 11 Jul 2016
    7.5
    High

    CVE-2016-3753

    Last Modified: 12 Apr 2025

    mediaserver in Android 4.x before 4.4.4 allows remote attackers to obtain sensitive information via unspecified vectors, aka internal bug 27210135.

    Published: 11 Jul 2016
    7.5
    High

    CVE-2016-3754

    Last Modified: 12 Apr 2025

    mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not limit process-memory usage, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28615448.

    Published: 11 Jul 2016
    7.5
    High

    CVE-2016-3755

    Last Modified: 12 Apr 2025

    decoder/ih264d_parse_pslice.c in mediaserver in Android 6.x before 2016-07-01 does not properly select concealment frames, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28470138.

    Published: 11 Jul 2016
    7.5
    High

    CVE-2016-3756

    Last Modified: 12 Apr 2025

    Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the number of partitions, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28556125.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3758

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in libdex/OptInvocation.cpp in DexClassLoader in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides a long filename, aka internal bug 27840771.

    Published: 11 Jul 2016
    3.3
    Low

    CVE-2016-3759

    Last Modified: 12 Apr 2025

    The Framework APIs in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to read backup data via a crafted application that leverages priv-app access to insert a backup transport, aka internal bug 28406080.

    Published: 11 Jul 2016
    7.5
    High

    CVE-2016-3760

    Last Modified: 12 Apr 2025

    Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairing that remains present during a session of the primary user, aka internal bug 27410683.

    Published: 11 Jul 2016
    4
    Medium

    CVE-2016-3761

    Last Modified: 12 Apr 2025

    NfcService.java in NFC in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive foreground-application information via a crafted background application, aka internal bug 28300969.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3762

    Last Modified: 12 Apr 2025

    The sockets subsystem in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application that uses (1) the AF_MSM_IPC socket class or (2) another socket class that is unrecognized by SELinux, aka internal bug 28612709.

    Published: 11 Jul 2016
    3.3
    Low

    CVE-2016-3763

    Last Modified: 12 Apr 2025

    net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating a server with a PAC script, aka internal bug 27593919.

    Published: 11 Jul 2016
    7.7
    High

    CVE-2016-3765

    Last Modified: 12 Apr 2025

    decoder/impeg2d_bitstream.c in mediaserver in Android 6.x before 2016-07-01 allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted application, aka internal bug 28168413.

    Published: 11 Jul 2016
    7.5
    High

    CVE-2016-3766

    Last Modified: 12 Apr 2025

    MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not check whether memory allocation succeeds, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28471206.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3767

    Last Modified: 12 Apr 2025

    The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28169363 and MediaTek internal bug ALPS02689526.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3768

    Last Modified: 12 Apr 2025

    The Qualcomm performance component in Android before 2016-07-05 on Nexus 5, 6, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28172137 and Qualcomm internal bug CR1010644.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3771

    Last Modified: 12 Apr 2025

    The MediaTek drivers in Android before 2016-07-05 on Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29007611 and MediaTek internal bug ALPS02703102.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3772

    Last Modified: 12 Apr 2025

    The MediaTek drivers in Android before 2016-07-05 on Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29008188 and MediaTek internal bug ALPS02703102.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3773

    Last Modified: 12 Apr 2025

    The MediaTek drivers in Android before 2016-07-05 on Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29008363 and MediaTek internal bug ALPS02703102.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3795

    Last Modified: 12 Apr 2025

    The MediaTek power driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085222 and MediaTek internal bug ALPS02677244.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3796

    Last Modified: 12 Apr 2025

    The MediaTek power driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 29008443 and MediaTek internal bug ALPS02677244.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3797

    Last Modified: 12 Apr 2025

    The Qualcomm Wi-Fi driver in Android before 2016-07-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085680 and Qualcomm internal bug CR1001450.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3798

    Last Modified: 12 Apr 2025

    The MediaTek hardware sensor driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28174490 and MediaTek internal bug ALPS02703105.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3799

    Last Modified: 12 Apr 2025

    The MediaTek video driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28175025 and MediaTek internal bug ALPS02693738.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3802

    Last Modified: 12 Apr 2025

    The kernel filesystem implementation in Android before 2016-07-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28271368.

    Published: 11 Jul 2016
    7.8
    High

    CVE-2016-3803

    Last Modified: 12 Apr 2025

    The kernel filesystem implementation in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28588434.

    Published: 11 Jul 2016