
CVE-2016-2425
https://notcve.org/view.php?id=CVE-2016-2425
18 Apr 2016 — mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 supports file:///data attachments, which allows attackers to obtain sensitive information via a crafted application, aka internal bugs 7154234 and 26989185. mail/compose/ComposeActivity.java en AOSP Mail en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-04-0... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-0839
https://notcve.org/view.php?id=CVE-2016-0839
18 Apr 2016 — post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25753245. post_proc/volume_listener.c en mediaserver en Android 6.x en versiones anteriores a 2016-04-01 no maneja correctamente el contexto de efecto borrado, lo que permite a atacantes remotos ejecutar código arbitrario o causar una denegación de serv... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-0834
https://notcve.org/view.php?id=CVE-2016-0834
18 Apr 2016 — An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26220548. Un códec multimedia no especificado en mediaserver en Android 6.x en versiones anteriores a 2016-04-01 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de un archivo multimedia manipulado, también conocido como... • http://nvidia.custhelp.com/app/answers/detail/a_id/4561 • CWE-20: Improper Input Validation •

CVE-2016-0850
https://notcve.org/view.php?id=CVE-2016-0850
18 Apr 2016 — The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to bypass intended pairing restrictions via a crafted device, aka internal bug 26551752. La funcionalidad PORCHE_PAIRING_CONFLICT en Bluetooth en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-04-01 permite a atacantes remotos eludi... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2421
https://notcve.org/view.php?id=CVE-2016-2421
18 Apr 2016 — Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410. Setup Wizard en Android 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-04-01 permite a atacantes físicamente próximos eludir el mecanismo de protección Factory Reset Protection y eliminar datos a través de vectores no especificados, también conocida... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2419
https://notcve.org/view.php?id=CVE-2016-2419
18 Apr 2016 — media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26323455. media/libmedia/IDrm.cpp en mediaserver en Android 6.x en versiones anteriores a 2016-04-01 no inicializa una determinada estr... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2414
https://notcve.org/view.php?id=CVE-2016-2414
18 Apr 2016 — The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177. La libería Minikin en Android 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-04-01 no considera correctamente los valores de tamaño negativos en... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-20: Improper Input Validation •

CVE-2016-0842
https://notcve.org/view.php?id=CVE-2016-0842
18 Apr 2016 — The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25818142. El decodificador H.264 en libstagefright en Android 6.x en versiones anteriores a 2016-04-01 no maneja correctamente los datos Memory Management Control Operation (MMCO), lo que permite a atacantes remotos ejecutar código arb... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-0843
https://notcve.org/view.php?id=CVE-2016-0843
18 Apr 2016 — The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application, aka internal bug 25801197. El administrador del rendimiento de eventos del procesador Qualcomm ARM en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-04-01 permite a atacantes obtener privil... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2409
https://notcve.org/view.php?id=CVE-2016-2409
18 Apr 2016 — A Texas Instruments (TI) haptic kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control over a service that can call this driver, aka internal bug 25981545. Un controlador háptico del kernel de Texas Instruments (TI) en Android 6.x en versiones anteriores a 2016-04-01 permite a atacantes obtener privilegios a través de una aplicación manipulada que se aprovecha del control sobre un servicio que puede llamar a este controlador, tambi... • http://source.android.com/security/bulletin/2016-04-02.html • CWE-264: Permissions, Privileges, and Access Controls •