Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-01-06 CVE-2015-6641 Information Exposure vulnerability in Google Android 6.0
Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.
high complexity
google CWE-200
3.1
2016-01-06 CVE-2015-6640 Permissions, Privileges, and Access Controls vulnerability in Google Android
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
local
low complexity
google CWE-264
7.8
2016-01-06 CVE-2015-6639 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.
local
low complexity
google CWE-264
7.8
2016-01-06 CVE-2015-6638 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.
local
low complexity
google CWE-264
7.8
2016-01-06 CVE-2015-6637 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.
local
low complexity
google CWE-264
7.8
2016-01-06 CVE-2015-6636 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 25070493 and 24686670.
network
low complexity
google CWE-119
critical
9.8
2016-01-06 CVE-2015-5310 Information Exposure vulnerability in Google Android
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service (ignored packets) via a WNM Sleep Mode response.
low complexity
google CWE-200
4.3
2016-01-05 CVE-2015-6861 Permissions, Privileges, and Access Controls vulnerability in Eucalyptus
HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user's account.
network
high complexity
eucalyptus CWE-264
7.5
2016-01-05 CVE-2015-6860 Permissions, Privileges, and Access Controls vulnerability in HP products
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859.
local
low complexity
hp CWE-264
8.4
2016-01-05 CVE-2015-6859 Permissions, Privileges, and Access Controls vulnerability in HP Network Switch Software 15.18.0
HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6860.
local
low complexity
hp CWE-264
7.8