NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
17467 | CVE-2016-10137 | An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of com.adups.fota.sysoper allows any app on the device to read, write, and delete files as the system user. In the com.adups.fota.sysoper app"s AndroidManifest.xml file, it sets the android:sharedUserId attribute to a value of android.uid.system which makes it execute as the system user, which is a very privileged user on the device. This allows a third-party app to read, write, and delete the user"s sent and received text messages and call log. This allows a third-party app to obtain PII from the user without permission to do so. | 2 | 7.2 | High | 2017-03-18 | 2017-03-15 | View | |
17979 | CVE-2016-1629 | Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors. | 2 | 10 | High | 2017-01-19 | 2016-12-05 | View | |
83771 | CVE-2017-6360 | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors. | 2 | 10 | High | 2017-03-29 | 2017-03-28 | View | |
19003 | CVE-2016-3157 | The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain sensitive information by leveraging I/O port access. | 2 | 7.2 | High | 2017-01-19 | 2016-12-02 | View | |
19515 | CVE-2016-3756 | Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the number of partitions, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28556125. | 2 | 7.8 | High | 2017-01-19 | 2016-07-11 | View |
Page 1919 of 17672, showing 5 records out of 88360 total, starting on record 9591, ending on 9595