Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-06-13 CVE-2016-2467 Unspecified vulnerability in Google Android
The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28029010.
local
low complexity
google
7.8
2016-06-13 CVE-2016-2466 Unspecified vulnerability in Google Android
The Qualcomm sound driver in Android before 2016-06-01 on Nexus 6 devices allows attackers to gain privileges via a crafted application, aka internal bug 27947307.
local
low complexity
google
7.8
2016-06-13 CVE-2016-2465 Unspecified vulnerability in Google Android
The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27407865.
local
low complexity
google
7.8
2016-06-13 CVE-2016-2464 Improper Input Validation vulnerability in Google Android
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
local
low complexity
google CWE-20
7.8
2016-06-13 CVE-2016-2463 Numeric Errors vulnerability in Google Android
Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a large memory allocation, aka internal bug 27855419.
local
low complexity
google CWE-189
8.4
2016-06-13 CVE-2016-2066 Improper Privilege Management vulnerability in Linux Kernel
Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application that makes an ioctl call.
local
low complexity
linux CWE-269
7.8
2016-06-13 CVE-2016-2061 Improper Privilege Management vulnerability in Linux Kernel
Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overflow and memory corruption) via a crafted application that triggers an msm_isp_axi_create_stream call.
local
low complexity
linux CWE-269
7.8
2016-06-10 CVE-2016-3706 Improper Input Validation vulnerability in multiple products
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion.
network
low complexity
opensuse gnu CWE-20
7.5
2016-06-10 CVE-2016-4494 Cross-Site Request Forgery (CSRF) vulnerability in KMC Controls Bac-5051E Firmware
Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows remote attackers to hijack the authentication of unspecified victims for requests that disclose the contents of a configuration file.
network
low complexity
kmc-controls CWE-352
8.8
2016-06-10 CVE-2016-1421 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IP Phone 8800 Series Firmware 11.0(1)
A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
7.5