Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-11-25 CVE-2016-6749 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6748 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6746 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6723 Improper Access Control vulnerability in Google Android
A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a remote attacker to use a specially crafted file to cause a device hang or reboot.
network
high complexity
google CWE-284
5.4
2016-11-25 CVE-2016-6721 Information Exposure vulnerability in Google Android 6.0/6.0.1/7.0
An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6719 Improper Access Control vulnerability in Google Android
An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to pair with any Bluetooth device without user consent.
network
google CWE-284
4.3
2016-11-25 CVE-2016-6718 Information Exposure vulnerability in Google Android
An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11-01 could enable a local malicious application to retrieve sensitive information without user interaction.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6716 Improper Access Control vulnerability in Google Android
An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent.
network
google CWE-284
4.3
2016-11-25 CVE-2016-6715 Improper Access Control vulnerability in Google Android
An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio without the user's permission.
network
google CWE-284
4.3
2016-11-25 CVE-2016-6710 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that isolate application data from other applications.
network
google CWE-200
4.3