
CVE-2016-2476
https://notcve.org/view.php?id=CVE-2016-2476
13 Jun 2016 — mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27207275. mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-06-01 no valida tamaños del buf... • http://source.android.com/security/bulletin/2016-06-01.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-2486
https://notcve.org/view.php?id=CVE-2016-2486
13 Jun 2016 — mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate the relationship between allocated memory and the frame size, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27793371. mp3dec/SoftMP3.cpp en libstagefright en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones an... • http://source.android.com/security/bulletin/2016-06-01.html • CWE-20: Improper Input Validation •

CVE-2016-2467
https://notcve.org/view.php?id=CVE-2016-2467
13 Jun 2016 — The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5 devices allows attackers to gain privileges via a crafted application, aka internal bug 28029010. El controlador de sonido Qualcomm en Android en versiones anteriores a 2016-06-01 en dispositivos Nexus 5 permite a atacantes obtener privilegios a través de una aplicación manipulada, también conocido como error interno 28029010. • http://source.android.com/security/bulletin/2016-06-01.html •

CVE-2016-2480
https://notcve.org/view.php?id=CVE-2016-2480
13 Jun 2016 — The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate certain OMX parameter data structures, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27532721. El componente mm-video-v4l2 vidc en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en vers... • http://source.android.com/security/bulletin/2016-06-01.html • CWE-20: Improper Input Validation •

CVE-2016-2475
https://notcve.org/view.php?id=CVE-2016-2475
13 Jun 2016 — The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to gain privileges for certain system calls via a crafted application, aka internal bug 26425765. El controlador Wi-Fi Broadcom en Android en versiones anteriores a 2016-06-01 en dispositivos Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player y Pixel C permite a atacantes obtener privilegios para ciertas llamadas al sistema a través ... • http://source.android.com/security/bulletin/2016-06-01.html • CWE-20: Improper Input Validation •

CVE-2016-2490
https://notcve.org/view.php?id=CVE-2016-2490
13 Jun 2016 — The NVIDIA camera driver in Android before 2016-06-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27533373. El controlador de cámara NVIDIA en Android en versiones anteriores a 2016-06-01 en dispositivos Nexus 9 permite a atacantes obtener privilegios a través de una aplicación manipulada, también conocido como error interno 27533373. • http://source.android.com/security/bulletin/2016-06-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2487
https://notcve.org/view.php?id=CVE-2016-2487
13 Jun 2016 — libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27833616. libstagefright en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-06-01 permite a atacantes obtener pri... • http://source.android.com/security/bulletin/2016-06-01.html • CWE-20: Improper Input Validation •

CVE-2016-2468
https://notcve.org/view.php?id=CVE-2016-2468
13 Jun 2016 — The Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows attackers to gain privileges via a crafted application, aka internal bug 27475454. El controlador GPU Qualcomm en Android en versiones anteriores a 2016-06-01 en dispositivos Nexus 5, 5X, 6, 6P y 7 permite a atacantes obtener privilegios a través de una aplicación manipulada, también conocido como error interno 27475454. • https://github.com/gitcollect/CVE-2016-2468 •

CVE-2016-2464
https://notcve.org/view.php?id=CVE-2016-2464
13 Jun 2016 — libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726. libvpx en libwebm en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-06-01 permite a atacantes remotos ejecu... • http://source.android.com/security/bulletin/2016-06-01.html • CWE-20: Improper Input Validation •

CVE-2016-2478
https://notcve.org/view.php?id=CVE-2016-2478
13 Jun 2016 — mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles pointers, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27475409. mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versione... • http://source.android.com/security/bulletin/2016-06-01.html • CWE-20: Improper Input Validation •