Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2015-10-06 CVE-2015-3870 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22771132.
network
low complexity
google CWE-119
critical
10.0
2015-10-06 CVE-2015-3869 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23036083.
network
low complexity
google CWE-119
critical
10.0
2015-10-06 CVE-2015-3868 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23270724.
network
low complexity
google CWE-119
critical
10.0
2015-10-06 CVE-2015-3867 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23213430.
network
low complexity
google CWE-119
critical
10.0
2015-10-06 CVE-2015-3865 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.
network
google CWE-264
critical
9.3
2015-10-06 CVE-2015-3862 Unspecified vulnerability in Google Android
mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22954006.
network
low complexity
google
5.0
2015-10-06 CVE-2015-3847 Permissions, Privileges, and Access Controls vulnerability in Google Android
Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.
network
low complexity
google CWE-264
6.4
2015-10-06 CVE-2015-3823 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.
network
low complexity
google CWE-119
critical
10.0
2015-10-02 CVE-2015-6602 Improper Input Validation vulnerability in Google Android
libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.
network
google CWE-20
critical
9.3
2015-10-02 CVE-2015-3876 Improper Input Validation vulnerability in Google Android
libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.
network
google CWE-20
critical
9.3