Vulnerabilities > Google > Android > 12.0

DATE CVE VULNERABILITY TITLE RISK
2016-11-25 CVE-2016-6708 Improper Access Control vulnerability in Google Android
An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode.
local
low complexity
google CWE-284
5.5
2016-11-25 CVE-2016-6701 Improper Access Control vulnerability in Google Android
A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing.
local
low complexity
google CWE-284
7.8
2016-11-25 CVE-2016-6698 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-3907 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-3906 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2016-11-25 CVE-2016-3904 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-6696 Improper Input Validation vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a large negative value for the data length, aka Qualcomm internal bug CR 1041130.
network
low complexity
google CWE-20
critical
9.8
2016-10-10 CVE-2016-6695 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted visualizer data length, aka Qualcomm internal bug CR 1033540.
network
low complexity
google CWE-119
critical
9.8
2016-10-10 CVE-2016-6694 Improper Input Validation vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via crafted parameter data, aka Qualcomm internal bug CR 1033525.
network
low complexity
google CWE-20
critical
9.8
2016-10-10 CVE-2016-6693 Improper Input Validation vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via an invalid data length, aka Qualcomm internal bug CR 1027585.
network
low complexity
google CWE-20
critical
9.8