Vulnerability index

Browse CVEs

1,055 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.0
CVE-2016-3757

The print_maps function in toolbox/lsof.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows user-…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3756

Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the …

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3755

decoder/ih264d_parse_pslice.c in mediaserver in Android 6.x before 2016-07-01 does not properly select concealment frames, which allows remote attack…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2016-3750

libs/binder/Parcel.cpp in the Parcels Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 d…

Mitigation only
Fix from $1,950 2016-07-11
Android CRITICAL 9.8
CVE-2016-3743

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-07-01 does not initialize certain data structures, which allows remote attackers to ex…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-3742

decoder/ih264d_process_intra_mb.c in mediaserver in Android 6.x before 2016-07-01 mishandles intra mode, which allows remote attackers to execute arb…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-3741

The H.264 decoder in mediaserver in Android 6.x before 2016-07-01 does not initialize certain slice data, which allows remote attackers to execute ar…

Mitigation only
Fix from $2,300 2016-07-11
Android MEDIUM 5.5
CVE-2016-2495

SampleTable.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allow…

Mitigation only
Fix from $1,600 2016-06-13
Android HIGH 7.8
CVE-2016-2487

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2486

mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 do…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2480

The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does n…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2478

mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2477

mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2475

The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allo…

Fix: after 6.0.1
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2464

libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attacke…

Mitigation only
Fix from $1,950 2016-06-13
Android MEDIUM 5.5
CVE-2016-2454

The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a…

Fix: after 6.0.1
Fix from $1,600 2016-05-09
Android MEDIUM 5.5
CVE-2016-2424

server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-0…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 6.2
CVE-2016-2414

The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in f…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 6.5
CVE-2016-2411

A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverag…

Mitigation only
Fix from $1,600 2016-04-18
Android HIGH 8.4
CVE-2016-0834

An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of ser…

Mitigation only
Fix from $1,950 2016-04-18
Android CRITICAL 9.8
CVE-2016-0815

The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H,…

Mitigation only
Fix from $2,300 2016-03-12
Chrome HIGH 8.8
CVE-2016-2844

WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wr…

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06
Android HIGH 8.8
CVE-2016-0802

The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to ex…

Fix: after 10.11.3
Fix from $1,950 2016-02-07
Chrome HIGH 7.6
CVE-2016-1612

The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility befo…

Fix: after 47.0.2526.106
Fix from $1,950 2016-01-25
Chrome HIGH 7.5
CVE-2015-1302

The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to …

Fix: after 46.0.2490.80
Fix from $1,950 2015-11-11
Chrome HIGH 7.5
CVE-2015-1303

bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information a…

Fix: after 45.0.2454.93
Fix from $1,950 2015-10-12
Android HIGH 10.0
CVE-2015-6598

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-6602

libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demo…

Fix: after 5.1.1
Fix from $1,950 2015-10-02
Android HIGH 9.3
CVE-2015-3876

libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.

Fix: after 5.1.1
Fix from $1,950 2015-10-02
Android HIGH 9.3
CVE-2015-3837

The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data…

Fix: after 5.1
Fix from $1,950 2015-10-01