Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-12-13 CVE-2016-6720 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-12-13 CVE-2016-6712 Improper Input Validation vulnerability in Google Android
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot.
local
low complexity
google CWE-20
5.5
2016-12-13 CVE-2016-6711 Improper Input Validation vulnerability in Google Android
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot.
local
low complexity
google CWE-20
5.5
2016-12-13 CVE-2016-6706 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process.
local
low complexity
google CWE-264
7.8
2016-12-13 CVE-2016-6699 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
A remote code execution vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing.
local
low complexity
google CWE-119
7.8
2016-12-13 CVE-2016-5647 Permissions, Privileges, and Access Controls vulnerability in Intel Graphics Driver
The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local users to cause a denial of service (crash) or gain privileges via a crafted D3DKMTEscape request.
local
low complexity
intel CWE-264
7.8
2016-12-13 CVE-2016-7440 The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
local
low complexity
mariadb oracle wolfssl debian
5.5
2016-12-13 CVE-2016-7439 Cryptographic Issues vulnerability in Wolfssl
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
local
low complexity
wolfssl CWE-310
5.5
2016-12-13 CVE-2016-7438 Cryptographic Issues vulnerability in Wolfssl
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
local
low complexity
wolfssl CWE-310
5.5
2016-12-13 CVE-2015-5073 Information Exposure vulnerability in multiple products
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.
network
low complexity
ibm pcre CWE-200
critical
9.1