
CVE-2016-4477 – Ubuntu Security Notice USN-3455-1
https://notcve.org/view.php?id=CVE-2016-4477
09 May 2016 — wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command. wpa_supplicant 0.4.0 hasta la versión 2.5 no rechaza caracteres \n y \r en parámetros passphrase, lo que permite a usuarios locales desencadenar la carga de librerías arbitrarias y consequently gain privileges... • http://source.android.com/security/bulletin/2016-05-01.html • CWE-19: Data Processing Errors •

CVE-2016-2452
https://notcve.org/view.php?id=CVE-2016-2452
09 May 2016 — codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 27662364 and 27843673. codecs/amrnb/dec/SoftAMR.cpp en libstagefright en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0... • http://source.android.com/security/bulletin/2016-05-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2439
https://notcve.org/view.php?id=CVE-2016-2439
09 May 2016 — Buffer overflow in btif/src/btif_dm.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows remote attackers to execute arbitrary code via a long PIN value, aka internal bug 27411268. Desbordamiento de buffer en btif/src/btif_dm.c en Bluetooth en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-05-01 permite a atacantes remotos ejecutar có... • http://source.android.com/security/bulletin/2016-05-01.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-2432
https://notcve.org/view.php?id=CVE-2016-2432
09 May 2016 — The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 6 and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 25913059. El componente Qualcomm TrustZone en Android en versiones anteriores a 2016-05-01 sobre dispositivos Nexus 6 y Android One permite a atacantes obtener privilegios a través de una aplicación manipulada, también conocido como error interno 25913059. • http://source.android.com/security/bulletin/2016-05-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2462
https://notcve.org/view.php?id=CVE-2016-2462
09 May 2016 — OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173. OpenSSLCipher.java en Conscrypt en Android 6.x en versiones anteriores a 2016-05-01 no maneja adecuadamente actualizaciones del array Additional Authenticated Data (AAD), lo que permite a atacantes suplantar la autenticación de mensaje a través de vectores no especificad... • http://source.android.com/security/bulletin/2016-05-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2428
https://notcve.org/view.php?id=CVE-2016-2428
09 May 2016 — libAACdec/src/aacdec_drc.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly limit the number of threads, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted media file, aka internal bug 26751339. libAACdec/src/aacdec_drc.cpp en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a... • http://source.android.com/security/bulletin/2016-05-01.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-2443
https://notcve.org/view.php?id=CVE-2016-2443
09 May 2016 — The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525. El controlador Qualcomm MDP en Android en versiones anteriores a 2016-05-01 sobre dispositivos Nexus 5 y Nexus 7 (2013) permite a atacantes obtener privilegios a través de una aplicación manipulada, también conocido como error interno 26404525. • http://source.android.com/security/bulletin/2016-05-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2454
https://notcve.org/view.php?id=CVE-2016-2454
09 May 2016 — The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024. El códec hardware de vídeo Qualcomm en Android en versiones anteriores a 2016-05-01 sobre dispositivos Nexus 5 permite a atacantes remotos to provocar una denegación de servicio (reinicio) a través de un archivo manipulado, también conocido como error interno 26221024. • http://source.android.com/security/bulletin/2016-05-01.html • CWE-20: Improper Input Validation •

CVE-2016-2429
https://notcve.org/view.php?id=CVE-2016-2429
09 May 2016 — libFLAC/stream_decoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not prevent free operations on uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted media file, aka internal bug 27211885. libFLAC/stream_decoder.c en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores... • http://source.android.com/security/bulletin/2016-05-01.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-2430
https://notcve.org/view.php?id=CVE-2016-2430
09 May 2016 — libbacktrace/Backtrace.cpp in debuggerd in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to gain privileges via an application containing a crafted symbol name, aka internal bug 27299236. libbacktrace/Backtrace.cpp en debuggerd en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-05-01 permite a atacantes obtener privilegios a través de u... • http://source.android.com/security/bulletin/2016-05-01.html • CWE-264: Permissions, Privileges, and Access Controls •