Vulnerability index

Browse CVEs

373 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Android HIGH 7.8
CVE-2016-2436

The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal b…

Fix: after 6.0.1
Fix from $1,950 2016-05-09
Android HIGH 7.8
CVE-2016-2435

The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal b…

Fix: after 6.0.1
Fix from $1,950 2016-05-09
Android HIGH 7.8
CVE-2016-2434

The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal b…

Fix: after 6.0.1
Fix from $1,950 2016-05-09
Android HIGH 7.8
CVE-2016-2432

The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted ap…

Fix: after 6.0.1
Fix from $1,950 2016-05-09
Android HIGH 7.8
CVE-2016-2431

The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain p…

Fix: after 6.0.1
Fix from $1,950 2016-05-09
Android HIGH 7.8
CVE-2016-2430

libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attacke…

Mitigation only
Fix from $1,950 2016-05-09
Android HIGH 7.8
CVE-2016-2060

server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM …

Fix: after 6.0.1
Fix from $1,950 2016-05-09
Android MEDIUM 6.1
CVE-2016-2423

server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not…

Mitigation only
Fix from $1,600 2016-04-18
Android HIGH 7.8
CVE-2016-2422

Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not prevent use of a Wi-Fi CA certificate i…

Mitigation only
Fix from $1,950 2016-04-18
Android MEDIUM 6.1
CVE-2016-2421

Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection pro…

Patch available
Fix from $1,600 2016-04-18
Android HIGH 7.8
CVE-2016-2420

rootdir/init.rc in Android 4.x before 4.4.4 does not ensure that the /data/tombstones directory exists for the Debuggerd component, which allows atta…

Mitigation only
Fix from $1,950 2016-04-18
Android CRITICAL 9.8
CVE-2016-2419

media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attack…

Mitigation only
Fix from $2,300 2016-04-18
Android CRITICAL 9.8
CVE-2016-2416

libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does n…

Mitigation only
Fix from $2,300 2016-04-18
Android CRITICAL 9.8
CVE-2016-2417EPSS 5%

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initia…

No fix yet
Fix from $2,300 2016-04-18
Android HIGH 7.8
CVE-2016-2413

media/libmedia/IOMX.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a handle poin…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 7.8
CVE-2016-2412

include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 7.4
CVE-2016-2410

A Qualcomm video kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control …

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.1
CVE-2016-2409

A Texas Instruments (TI) haptic kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that lev…

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.8
CVE-2016-0850

The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0847

The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to spoof the originating telephon…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0846

libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-0…

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0844

The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privi…

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0843

The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 a…

Patch available
Fix from $1,950 2016-04-18
Android MEDIUM 6.1
CVE-2016-0832

Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection pr…

Mitigation only
Fix from $1,600 2016-03-12
Android HIGH 7.8
CVE-2016-0826

libcameraservice in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not require use of the ICameraSe…

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.0
CVE-2016-0822

The MediaTek connectivity kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application that leverag…

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.8
CVE-2016-0820

The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 2…

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.8
CVE-2016-0819

The Qualcomm performance component in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows attackers to gain privilege…

Mitigation only
Fix from $1,950 2016-03-12
Chrome CRITICAL 9.8
CVE-2016-1636

The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623.75 relies on memory-cache in…

Fix: after 48.0.2564.116
Fix from $2,300 2016-03-06
Chrome HIGH 8.8
CVE-2016-1632

The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass inte…

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06