Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-11-03 CVE-2015-8074 Information Exposure vulnerability in Google Android
mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than CVE-2015-6611.
network
low complexity
google CWE-200
5.0
2015-11-03 CVE-2015-6614 Permissions, Privileges, and Access Controls vulnerability in Google Android 5.0/5.1
Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, perform expensive data transfers, or cause a denial of service (call-reception outage or mute manipulation), via a crafted application, aka internal bug 21900139.
network
google CWE-264
5.8
2015-11-03 CVE-2015-6613 Command Injection vulnerability in Google Android
Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24371736.
network
high complexity
google CWE-77
5.1
2015-11-03 CVE-2015-6611 Information Exposure vulnerability in Google Android
mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23905951, 23912202, 23953967, 23696300, 23600291, 23756261, 23541506, 23284974, 23542351, and 23542352, a different vulnerability than CVE-2015-8074.
network
low complexity
google CWE-200
5.0
2015-10-15 CVE-2015-7628 Information Exposure vulnerability in Adobe products
Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
network
low complexity
adobe apple microsoft linux google CWE-200
5.0
2015-10-06 CVE-2015-7718 Unspecified vulnerability in Google Android
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.
network
low complexity
google
5.0
2015-10-06 CVE-2015-6607 Permissions, Privileges, and Access Controls vulnerability in Sqlite
SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586.
6.8
2015-10-06 CVE-2015-6605 Unspecified vulnerability in Google Android
mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bugs 20915134 and 23142203, a different vulnerability than CVE-2015-7718.
network
low complexity
google
5.0
2015-10-06 CVE-2015-3878 Permissions, Privileges, and Access Controls vulnerability in Google Android 5.0/5.1
Media Projection in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to bypass an intended screen-recording warning feature and obtain sensitive screen-snapshot information via a crafted application that references a long application name, aka internal bug 23345192.
network
google CWE-264
4.3
2015-10-06 CVE-2015-3862 Unspecified vulnerability in Google Android
mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22954006.
network
low complexity
google
5.0