Vulnerabilities > Google > Android

DATE CVE VULNERABILITY TITLE RISK
2016-05-09 CVE-2016-2440 Permissions, Privileges, and Access Controls vulnerability in Google Android
libs/binder/IPCThreadState.cpp in Binder in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 mishandles object references, which allows attackers to gain privileges via a crafted application, aka internal bug 27252896.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2439 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
Buffer overflow in btif/src/btif_dm.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows remote attackers to execute arbitrary code via a long PIN value, aka internal bug 27411268.
low complexity
google CWE-119
8.8
2016-05-09 CVE-2016-2437 Permissions, Privileges, and Access Controls vulnerability in Google Android
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27436822.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2436 Permissions, Privileges, and Access Controls vulnerability in Google Android
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27299111.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2435 Permissions, Privileges, and Access Controls vulnerability in Google Android
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27297988.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2434 Permissions, Privileges, and Access Controls vulnerability in Google Android
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27251090.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2432 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2431 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 24968809.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2430 Permissions, Privileges, and Access Controls vulnerability in Google Android
libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to gain privileges via an application containing a crafted symbol name, aka internal bug 27299236.
local
low complexity
google CWE-264
7.8
2016-05-09 CVE-2016-2429 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libFLAC/stream_decoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not prevent free operations on uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted media file, aka internal bug 27211885.
network
low complexity
google CWE-119
critical
9.8