Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2016-08-05 CVE-2016-3844 Permissions, Privileges, and Access Controls vulnerability in Google Android
mediaserver in Android before 2016-08-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28299517.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3843 Permissions, Privileges, and Access Controls vulnerability in Google Android
Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka Android internal bugs 28086229 and 29119870 and Qualcomm internal bug CR1011071.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3842 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28377352 and Qualcomm internal bug CR1002974.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3840 Permissions, Privileges, and Access Controls vulnerability in Google Android
Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.
network
low complexity
google CWE-264
critical
10.0
2016-08-05 CVE-2016-3839 Improper Access Control vulnerability in Google Android
Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a crafted application that sends a signal to a Bluetooth process, aka internal bug 28885210.
network
google CWE-284
4.3
2016-08-05 CVE-2016-3838 Improper Access Control vulnerability in Google Android 6.0/6.0.1
Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.
network
google CWE-284
4.3
2016-08-05 CVE-2016-3837 Information Exposure vulnerability in Google Android
service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application that provides a MAC address with too few characters, aka internal bug 28164077.
network
google CWE-200
4.3
2016-08-05 CVE-2016-3836 Information Exposure vulnerability in Google Android
The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka internal bug 28592402.
network
google CWE-200
4.3
2016-08-05 CVE-2016-3835 Information Exposure vulnerability in Google Android
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 28920116.
network
google CWE-200
4.3
2016-08-05 CVE-2016-3834 Information Exposure vulnerability in Google Android
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, aka internal bug 28466701.
network
google CWE-200
4.3