Vulnerabilities > Google > Android > 2.2.3

DATE CVE VULNERABILITY TITLE RISK
2016-07-11 CVE-2016-3771 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek drivers in Android before 2016-07-05 on Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29007611 and MediaTek internal bug ALPS02703102.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3770 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek drivers in Android before 2016-07-05 on Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28346752 and MediaTek internal bug ALPS02703102.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3769 Permissions, Privileges, and Access Controls vulnerability in Google Android
The NVIDIA video driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28376656.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3768 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm performance component in Android before 2016-07-05 on Nexus 5, 6, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28172137 and Qualcomm internal bug CR1010644.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-3767 Resource Management Errors vulnerability in Google Android
The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28169363 and MediaTek internal bug ALPS02689526.
network
google CWE-399
critical
9.3
2016-07-11 CVE-2016-2505 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
mpeg2ts/ATSParser.cpp in libstagefright in mediaserver in Android 6.x before 2016-07-01 does not validate a certain section length, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28333006.
network
google CWE-119
critical
9.3
2016-07-11 CVE-2016-2503 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm GPU driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28084795 and Qualcomm internal bug CR1006067.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-2502 Permissions, Privileges, and Access Controls vulnerability in Google Android
drivers/usb/gadget/f_serial.c in the Qualcomm USB driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a large size in a GSER_IOCTL ioctl call, aka Android internal bug 27657963 and Qualcomm internal bug CR997044.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-2501 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm camera driver in Android before 2016-07-05 on Nexus 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, aka Android internal bug 27890772 and Qualcomm internal bug CR1001092.
network
google CWE-264
critical
9.3
2016-07-11 CVE-2016-2068 Integer Overflow or Wraparound vulnerability in multiple products
The MSM QDSP6 audio driver (aka sound driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (integer overflow, and buffer overflow or buffer over-read) via a crafted application that performs a (1) AUDIO_EFFECTS_WRITE or (2) AUDIO_EFFECTS_READ operation, aka Qualcomm internal bug CR1006609.
network
google linux CWE-190
6.8