Vulnerabilities > Google

DATE CVE VULNERABILITY TITLE RISK
2016-05-14 CVE-2016-1660 Improper Input Validation vulnerability in multiple products
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted web site.
network
low complexity
opensuse redhat google CWE-20
8.8
2016-05-09 CVE-2016-4477 Data Processing Errors vulnerability in Google Android
wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.
local
low complexity
google CWE-19
7.8
2016-05-09 CVE-2016-2462 Permissions, Privileges, and Access Controls vulnerability in Google Android 6.0/6.0.1
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173.
local
high complexity
google CWE-264
7.0
2016-05-09 CVE-2016-2461 Permissions, Privileges, and Access Controls vulnerability in Google Android 6.0/6.0.1
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bugs 27324690 and 27696681.
local
high complexity
google CWE-264
7.0
2016-05-09 CVE-2016-2460 Information Exposure vulnerability in Google Android
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27555981.
local
low complexity
google CWE-200
5.5
2016-05-09 CVE-2016-2459 Information Exposure vulnerability in Google Android
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27556038.
local
low complexity
google CWE-200
5.5
2016-05-09 CVE-2016-2458 Information Exposure vulnerability in Google Android
The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive information via a crafted application, related to ComposeActivity.java and ComposeActivityEmail.java, aka internal bug 27335139.
local
low complexity
google CWE-200
5.5
2016-05-09 CVE-2016-2457 Permissions, Privileges, and Access Controls vulnerability in Google Android
server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended restrictions on Wi-Fi configuration changes by leveraging guest access, aka internal bug 27411179.
local
low complexity
google CWE-264
5.5
2016-05-09 CVE-2016-2456 Permissions, Privileges, and Access Controls vulnerability in Google Android
The MediaTek Wi-Fi driver in Android before 2016-05-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 27275187.
local
high complexity
google CWE-264
7.0
2016-05-09 CVE-2016-2454 Improper Input Validation vulnerability in Google Android
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
local
low complexity
google CWE-20
5.5