
CVE-2017-0409
https://notcve.org/view.php?id=CVE-2017-0409
08 Feb 2017 — A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31999646. • http://www.securityfocus.com/bid/96091 •

CVE-2017-0423
https://notcve.org/view.php?id=CVE-2017-0423
08 Feb 2017 — An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability in the Bluetooth stack. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32612586. • http://www.securityfocus.com/bid/96102 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2014-9914
https://notcve.org/view.php?id=CVE-2014-9914
07 Feb 2017 — Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets. Condición de carrera en la función ip4_datagram_release_cb en net/ipv4/datagram.c en el kernel de Linux en versiones anteriores a 3.15.2 permite a usuarios locales obtener privilegios o p... • http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9709674e68646cee5a24e3000b3558d25412203a • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-416: Use After Free •

CVE-2016-10044 – Ubuntu Security Notice USN-3422-2
https://notcve.org/view.php?id=CVE-2016-10044
07 Feb 2017 — The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call. La función aio_mount en fs/aio.c en el kernel de Linux en versiones anteriores a 4.7.7 no restringe adecuadamente el acceso de ejecución, lo que facilita a usuarios locales eludir restricciones de política destinadas SELinux W^X, y consecuentemente... • http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=22f6b4d34fcf039c63a94e7670e0da24f8575a5a • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-6604
https://notcve.org/view.php?id=CVE-2016-6604
30 Jan 2017 — NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors. The Samsung ID is SVE-2016-6382. La desreferencia de puntero NULL en el controlador Samsung Exynos fimg2d para Android L (5.0/5.1) y M(6.0) permite a los atacantes tener un impacto no especificado mediante vectores desconocidos. La ID de Samsung es SVE-2016-6382. • http://security.samsungmobile.com/smrupdate.html#SMR-AUG-2016 • CWE-476: NULL Pointer Dereference •

CVE-2016-8411
https://notcve.org/view.php?id=CVE-2016-8411
27 Jan 2017 — Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. References: QC CR#912775. • http://www.securityfocus.com/bid/94684 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-9909
https://notcve.org/view.php?id=CVE-2014-9909
18 Jan 2017 — An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31676542. • http://www.securityfocus.com/bid/94685 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-9910
https://notcve.org/view.php?id=CVE-2014-9910
18 Jan 2017 — An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31746399. • http://www.securityfocus.com/bid/94685 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2017-0398
https://notcve.org/view.php?id=CVE-2017-0398
13 Jan 2017 — An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android IDs: A-32438594, A-32635664. • http://www.securityfocus.com/bid/95226 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-8467
https://notcve.org/view.php?id=CVE-2016-8467
13 Jan 2017 — An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completely permanent or requiring re-flashing the entire operating system). Product: Android. Versions: N/A. Android ID: A-30308784. • https://github.com/roeeh/bootmodechecker • CWE-264: Permissions, Privileges, and Access Controls •