Vulnerabilities > Google > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-08-06 CVE-2014-9864 Improper Input Validation vulnerability in Google Android
drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate ioctl calls, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28747998 and Qualcomm internal bug CR561841.
network
google CWE-20
critical
9.3
2016-08-06 CVE-2014-9863 Integer Overflow or Wraparound vulnerability in Google Android
Integer underflow in the diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android internal bug 28768146 and Qualcomm internal bug CR549470.
network
google CWE-190
critical
9.3
2016-08-05 CVE-2016-3857 Permissions, Privileges, and Access Controls vulnerability in Google Android
The kernel in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 28522518.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3851 Permissions, Privileges, and Access Controls vulnerability in Google Android
The LG Electronics bootloader Android before 2016-08-05 on Nexus 5X devices allows attackers to gain privileges by leveraging access to a privileged process, aka internal bug 29189941.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3845 Permissions, Privileges, and Access Controls vulnerability in Google Android
The video driver in the kernel in Android before 2016-08-05 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28399876.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3844 Permissions, Privileges, and Access Controls vulnerability in Google Android
mediaserver in Android before 2016-08-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28299517.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3843 Permissions, Privileges, and Access Controls vulnerability in Google Android
Android before 2016-08-05 does not properly restrict code execution in a kernel context, which allows attackers to gain privileges via a crafted application, as demonstrated by the kernel performance subsystem and the Qualcomm performance component, aka Android internal bugs 28086229 and 29119870 and Qualcomm internal bug CR1011071.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3842 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Qualcomm GPU driver in Android before 2016-08-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28377352 and Qualcomm internal bug CR1002974.
network
google CWE-264
critical
9.3
2016-08-05 CVE-2016-3840 Permissions, Privileges, and Access Controls vulnerability in Google Android
Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.
network
low complexity
google CWE-264
critical
10.0
2016-08-05 CVE-2016-3833 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Shell component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does not properly manage the MANAGE_USERS and CREATE_USERS permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka internal bug 29189712.
network
google CWE-264
critical
9.3