Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-10-13 CVE-2016-8563 Improper Input Validation vulnerability in Siemens Automation License Manager 5.3
Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.
network
low complexity
siemens CWE-20
7.5
2016-10-10 CVE-2016-1000216 OS Command Injection vulnerability in Ruckus Wireless H500
Ruckus Wireless H500 web management interface authenticated command injection
network
low complexity
ruckus CWE-78
8.8
2016-10-10 CVE-2016-8101 Permissions, Privileges, and Access Controls vulnerability in Intel Solid-State Drive Toolbox 1.0/3.3.6
The updater subsystem in Intel SSD Toolbox before 3.3.7 allows local users to gain privileges via unspecified vectors.
local
low complexity
intel CWE-264
7.8
2016-10-10 CVE-2016-6680 Information Exposure vulnerability in Google Android
CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obtain sensitive information via a crafted application that makes an iw_set_priv ioctl call, aka Android internal bug 29982678 and Qualcomm internal bug CR 1048052.
local
low complexity
google CWE-200
7.8
2016-10-10 CVE-2016-6676 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
Off-by-one error in CORE/HDD/src/wlan_hdd_cfg.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted application that makes a GET_CFG ioctl call, aka Android internal bug 30874066 and Qualcomm internal bug CR 1000853.
local
low complexity
google CWE-119
7.8
2016-10-10 CVE-2016-6675 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
Off-by-one error in CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted application that makes a linkspeed ioctl call, aka Android internal bug 30873776 and Qualcomm internal bug CR 1000861.
local
low complexity
google CWE-119
7.8
2016-10-10 CVE-2016-6674 Improper Input Validation vulnerability in Google Android
system_server in Android before 2016-10-05 on Nexus devices allows attackers to gain privileges via a crafted application, aka internal bug 30445380.
local
low complexity
google CWE-20
7.8
2016-10-10 CVE-2016-6673 Permissions, Privileges, and Access Controls vulnerability in Google Android
The NVIDIA camera driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 30204201.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-6672 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 30537088.
local
low complexity
google CWE-264
7.8
2016-10-10 CVE-2016-3940 Permissions, Privileges, and Access Controls vulnerability in Google Android
The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 6P and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 30141991.
local
low complexity
google CWE-264
7.8