Vulnerabilities > Google > Android > 1.0

DATE CVE VULNERABILITY TITLE RISK
2017-01-12 CVE-2016-8433 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
google CWE-264
critical
9.3
2017-01-12 CVE-2016-8423 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
google CWE-264
critical
9.3
2017-01-12 CVE-2016-8422 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
google CWE-264
critical
9.3
2017-01-12 CVE-2016-8396 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2017-01-12 CVE-2016-6788 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the MediaTek I2C driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
high complexity
google CWE-264
7.6
2017-01-12 CVE-2016-6783 Improper Access Control vulnerability in Google Android
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
network
google CWE-284
critical
9.3
2017-01-12 CVE-2016-6774 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Package Manager could enable a local malicious application to bypass operating system protections that isolate application data from other applications.
network
high complexity
google CWE-200
2.6
2016-12-13 CVE-2016-6706 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process.
network
google CWE-264
critical
9.3
2016-12-13 CVE-2016-6699 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
A remote code execution vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing.
network
google CWE-119
critical
9.3
2016-12-08 CVE-2015-8967 Permissions, Privileges, and Access Controls vulnerability in multiple products
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
local
low complexity
google linux CWE-264
7.8