Vulnerability index

Browse CVEs

386 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-3813

The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3812

The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted ap…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3810

The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted applicat…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3809

The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, an…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android HIGH 7.7
CVE-2016-3765

decoder/impeg2d_bitstream.c in mediaserver in Android 6.x before 2016-07-01 allows attackers to obtain sensitive information from process memory or c…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3753

mediaserver in Android 4.x before 4.4.4 allows remote attackers to obtain sensitive information via unspecified vectors, aka internal bug 27210135.

Mitigation only
Fix from $1,950 2016-07-11
Android MEDIUM 5.5
CVE-2016-2500

Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allow…

Mitigation only
Fix from $1,600 2016-06-13
Android MEDIUM 5.5
CVE-2016-2499

AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does …

Mitigation only
Fix from $1,600 2016-06-13
Android MEDIUM 5.5
CVE-2016-2498

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a c…

Patch available
Fix from $1,600 2016-06-13
Chrome MEDIUM 6.5
CVE-2016-1677

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to o…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Android MEDIUM 5.5
CVE-2016-2460

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structure…

Mitigation only
Fix from $1,600 2016-05-09
Android MEDIUM 5.5
CVE-2016-2459

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structure…

Mitigation only
Fix from $1,600 2016-05-09
Android MEDIUM 5.5
CVE-2016-2458

The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attach…

Mitigation only
Fix from $1,600 2016-05-09
Chrome HIGH 8.1
CVE-2016-1651

fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc42…

Fix: after 49.0.2623.112
Fix from $1,950 2016-04-18
Android MEDIUM 5.5
CVE-2016-2426

server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 5.5
CVE-2016-2425

mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 support…

Patch available
Fix from $1,600 2016-04-18
Android MEDIUM 5.5
CVE-2016-2415

exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 5.5
CVE-2016-0831

The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 201…

Mitigation only
Fix from $1,600 2016-03-12
Android HIGH 7.5
CVE-2016-0829

The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 …

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.5
CVE-2016-0828

The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x bef…

Mitigation only
Fix from $1,950 2016-03-12
Android MEDIUM 5.3
CVE-2016-0825

The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leve…

Mitigation only
Fix from $1,600 2016-03-12
Android MEDIUM 5.3
CVE-2016-0824

libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified …

Mitigation only
Fix from $1,600 2016-03-12
Chrome MEDIUM 5.3
CVE-2016-2845

The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in th…

Fix: after 48.0.2564.116
Fix from $1,600 2016-03-06
Chrome MEDIUM 6.5
CVE-2016-1637

The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calcul…

Fix: after 48.0.2564.116
Fix from $1,600 2016-03-06
Android HIGH 7.5
CVE-2016-0811

Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows …

Mitigation only
Fix from $1,950 2016-02-07
Chrome MEDIUM 6.5
CVE-2016-1618

Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, whi…

Fix: after 47.0.2526.106
Fix from $1,600 2016-01-25
Android MEDIUM 5.0
CVE-2015-6632

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently byp…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6631

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently byp…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6629

Wi-Fi in Android 5.x before 5.1.1 LMY48Z allows attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining Signa…

Fix: after 5.1
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6628

Media Framework in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an…

Fix: 5.1.1+
Fix from $1,600 2015-12-08