CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93526  CVE-2016-6706  Candidate  An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-31385713.  Assigned (20160811)  None (candidate not yet proposed)    View
93527  CVE-2016-6707  Candidate  An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-31350622.  Assigned (20160811)  None (candidate not yet proposed)    View
93528  CVE-2016-6708  Candidate  An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypass of user interaction requirements for any developer or security setting modifications. Android ID: A-30693465.  Assigned (20160811)  None (candidate not yet proposed)    View
93529  CVE-2016-6709  Candidate  An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission. Android ID: A-31081987.  Assigned (20160811)  None (candidate not yet proposed)    View
93530  CVE-2016-6710  Candidate  An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Android ID: A-30537115.  Assigned (20160811)  None (candidate not yet proposed)    View

Page 18706 of 20943, showing 5 records out of 104715 total, starting on record 93526, ending on 93530

Actions