Vulnerabilities > Google > Android > 4.3

DATE CVE VULNERABILITY TITLE RISK
2016-02-07 CVE-2016-0803 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a large memory allocation in the (1) SoftMPEG4Encoder or (2) SoftVPXEncoder component, aka internal bug 25812794.
network
low complexity
google CWE-119
critical
10.0
2015-12-08 CVE-2015-8505 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
mediaserver in Android before 5.1.1 LMY48Z allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 17769851, a different vulnerability than CVE-2015-6616, CVE-2015-8506, and CVE-2015-8507.
network
google CWE-119
critical
9.3
2015-12-08 CVE-2015-6634 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
The display drivers in Android before 5.1.1 LMY48Z allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24163261.
network
google CWE-119
critical
9.3
2015-12-08 CVE-2015-6629 Information Exposure vulnerability in Google Android
Wi-Fi in Android 5.x before 5.1.1 LMY48Z allows attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22667667.
network
low complexity
google CWE-200
5.0
2015-11-03 CVE-2015-8074 Information Exposure vulnerability in Google Android
mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than CVE-2015-6611.
network
low complexity
google CWE-200
5.0
2015-11-03 CVE-2015-6609 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.
network
low complexity
google CWE-119
critical
10.0
2015-10-06 CVE-2015-7718 Unspecified vulnerability in Google Android
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.
network
low complexity
google
5.0
2015-10-06 CVE-2015-7717 Permissions, Privileges, and Access Controls vulnerability in Google Android
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.
network
google CWE-264
critical
9.3
2015-10-06 CVE-2015-7716 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulnerability than CVE-2015-3873.
network
low complexity
google CWE-119
critical
10.0
2015-10-06 CVE-2015-6606 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22301786.
network
google CWE-264
critical
9.3