Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-07-11 CVE-2016-3816 Information Exposure vulnerability in Google Android
The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28402240.
network
google CWE-200
4.3
2016-07-11 CVE-2016-3815 Information Exposure vulnerability in Google Android
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28522274.
network
google CWE-200
4.3
2016-07-11 CVE-2016-3814 Information Exposure vulnerability in Google Android
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28193342.
network
google CWE-200
4.3
2016-07-11 CVE-2016-3813 Information Exposure vulnerability in Google Android
The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28172322 and Qualcomm internal bug CR1010222.
network
google CWE-200
4.3
2016-07-11 CVE-2016-3812 Information Exposure vulnerability in Google Android
The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28174833 and MediaTek internal bug ALPS02688832.
network
google CWE-200
4.3
2016-07-11 CVE-2016-3810 Information Exposure vulnerability in Google Android
The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28175522 and MediaTek internal bug ALPS02694389.
network
google CWE-200
4.3
2016-07-11 CVE-2016-3809 Information Exposure vulnerability in Google Android
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.
network
google CWE-200
4.3
2016-07-11 CVE-2016-3765 Resource Management Errors vulnerability in Google Android 6.0/6.0.1
decoder/impeg2d_bitstream.c in mediaserver in Android 6.x before 2016-07-01 allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted application, aka internal bug 28168413.
network
low complexity
google CWE-399
6.4
2016-07-11 CVE-2016-3764 Improper Input Validation vulnerability in Google Android
media/libmediaplayerservice/MetadataRetrieverClient.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to obtain sensitive pointer information via a crafted application, aka internal bug 28377502.
network
low complexity
google CWE-20
5.0
2016-07-11 CVE-2016-3763 Improper Input Validation vulnerability in Google Android
net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating a server with a PAC script, aka internal bug 27593919.
network
low complexity
google CWE-20
5.0