Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2016-10-10 CVE-2016-3922 Permissions, Privileges, and Access Controls vulnerability in Google Android 6.0/6.0.1/7.0
libril/RilSapSocket.cpp in Telephony in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 relies on variable-length arrays, which allows attackers to gain privileges via a crafted application, aka internal bug 30202619.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-3921 Permissions, Privileges, and Access Controls vulnerability in Google Android
libsysutils/src/FrameworkListener.cpp in Framework Listener in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 29831647.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-3920 Improper Input Validation vulnerability in Google Android
id3/ID3.cpp in libstagefright in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 30744884.
local
low complexity
google CWE-20
5.5
2016-10-10 CVE-2016-3918 Information Exposure vulnerability in Google Android
email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not ensure that certain values are integers, which allows attackers to read arbitrary attachments via a crafted application that provides a pathname value, aka internal bug 30745403.
local
low complexity
google CWE-200
5.5
2016-10-10 CVE-2016-3917 Permissions, Privileges, and Access Controls vulnerability in Google Android 6.0.1/7.0
The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process, which allows physically proximate attackers to authenticate as an arbitrary user by leveraging lockscreen access, aka internal bug 30744668.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-3916 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30741779.
local
low complexity
google CWE-119
7.8
2016-10-10 CVE-2016-3915 Permissions, Privileges, and Access Controls vulnerability in Google Android
camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30591838.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-3914 Race Condition vulnerability in Google Android
Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application that modifies a database between two open operations, aka internal bug 30481342.
local
low complexity
google CWE-362
7.8
2016-10-10 CVE-2016-3913 Permissions, Privileges, and Access Controls vulnerability in Google Android
media/libmediaplayerservice/MediaPlayerService.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate a certain static_cast operation, which allows attackers to gain privileges via a crafted application, aka internal bug 30204103.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-3912 Permissions, Privileges, and Access Controls vulnerability in Google Android
The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allow attackers to gain privileges via a crafted application, aka internal bug 30202481.
local
low complexity
google CWE-264
7.8