Vulnerabilities > Google > Android > 4.4.1

DATE CVE VULNERABILITY TITLE RISK
2016-06-13 CVE-2016-2466 Unspecified vulnerability in Google Android
The Qualcomm sound driver in Android before 2016-06-01 on Nexus 6 devices allows attackers to gain privileges via a crafted application, aka internal bug 27947307.
local
low complexity
google
7.8
2016-06-13 CVE-2016-2465 Unspecified vulnerability in Google Android
The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27407865.
local
low complexity
google
7.8
2016-06-13 CVE-2016-2463 Numeric Errors vulnerability in Google Android
Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a large memory allocation, aka internal bug 27855419.
local
low complexity
google CWE-189
8.4
2016-05-09 CVE-2016-2460 Information Exposure vulnerability in Google Android
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27555981.
local
low complexity
google CWE-200
5.5
2016-05-09 CVE-2016-2459 Information Exposure vulnerability in Google Android
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27556038.
local
low complexity
google CWE-200
5.5
2016-05-09 CVE-2016-2456 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27275187.
local
high complexity
google CWE-264
7.0
2016-05-09 CVE-2016-2454 Improper Input Validation vulnerability in Google Android
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
local
low complexity
google CWE-20
5.5
2016-05-09 CVE-2016-2452 Permissions, Privileges, and Access Controls vulnerability in Google Android
codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 27662364 and 27843673.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2451 Permissions, Privileges, and Access Controls vulnerability in Google Android
codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate VPX output buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27597103.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2450 Permissions, Privileges, and Access Controls vulnerability in Google Android
codecs/on2/enc/SoftVPXEncoder.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27569635.
local
low complexity
google CWE-264
7.8