Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-11-25 CVE-2016-6703 Improper Access Control vulnerability in Google Android
A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker using a specially crafted payload to execute arbitrary code in the context of an unprivileged process.
local
low complexity
google CWE-284
7.8
2016-11-25 CVE-2016-6702 Improper Access Control vulnerability in Google Android
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process.
local
low complexity
google CWE-284
7.8
2016-11-25 CVE-2016-6701 Improper Access Control vulnerability in Google Android
A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing.
local
low complexity
google CWE-284
7.8
2016-11-25 CVE-2016-6700 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable a local malicious application to execute arbitrary code within the context of a privileged process.
local
low complexity
google CWE-264
7.8
2016-11-25 CVE-2016-3904 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
low complexity
google CWE-264
7.8
2016-11-25 CVE-2016-3025 7PK - Security Features vulnerability in IBM products
IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
network
high complexity
ibm CWE-254
8.1
2016-11-25 CVE-2016-2988 Permissions, Privileges, and Access Controls vulnerability in IBM Tivoli Storage Manager for Virtual Environments 6.4/7.1
IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.4.x before 6.4.3.4 and 7.1.x before 7.1.6 allows remote authenticated users to bypass a TSM credential requirement and obtain administrative access by leveraging multiple simultaneous logins.
network
high complexity
ibm CWE-264
8.5
2016-11-25 CVE-2016-2985 Permissions, Privileges, and Access Controls vulnerability in IBM General Parallel File System and Spectrum Scale
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program.
local
high complexity
ibm CWE-264
7.0
2016-11-25 CVE-2016-2984 Permissions, Privileges, and Access Controls vulnerability in IBM General Parallel File System and Spectrum Scale
IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program.
local
high complexity
ibm CWE-264
7.0
2016-11-23 CVE-2016-1248 Improper Input Validation vulnerability in multiple products
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.
local
low complexity
vim debian CWE-20
7.8