CVE-2016-6707 – Google Android - Inter-Process munmap with User-Controlled Size in android.graphics.Bitmap
https://notcve.org/view.php?id=CVE-2016-6707
An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-31350622. Una vulnerabilidad de elevación de privilegio en System Server en Android 6.x en versiones anteriores a 01-11-2016 y 7.0 en versiones anteriores a 01-11-2016 podría habilitar a una aplicación maliciosa local a ejecutar código arbitrario dentro del contexto de un proceso privilegiado. Este problema está clasificado como High porque puede ser usado para obtener acceso local a capacidades elevadas, las cuales no son normalmente accesibles a aplicaciones de terceros. • https://www.exploit-db.com/exploits/40874 http://www.securityfocus.com/bid/94164 https://bugs.chromium.org/p/project-zero/issues/detail?id=928 https://googleprojectzero.blogspot.com/2016/12/bitunmap-attacking-android-ashmem.html https://source.android.com/security/bulletin/2016-11-01.html • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-6732
https://notcve.org/view.php?id=CVE-2016-6732
An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30906599. References: NVIDIA N-CVE-2016-6732. Una vulnerabilidad de elevación de privilegio en el controlador NVIDIA GPU en Android en versiones anteriores a 05-11-2016 podría habilitar a una aplicación maliciosa local a ejecutar código arbitrario dentro del contexto del kernel. • http://www.securityfocus.com/bid/94140 https://source.android.com/security/bulletin/2016-11-01.html • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-6733
https://notcve.org/view.php?id=CVE-2016-6733
An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30906694. References: NVIDIA N-CVE-2016-6733. Una vulnerabilidad de elevación de privilegio en el controlador NVIDIA GPU en Android en versiones anteriores a 05-11-2016 podría habilitar a una aplicación maliciosa local a ejecutar código arbitrario dentro del contexto del kernel. • http://www.securityfocus.com/bid/94140 https://source.android.com/security/bulletin/2016-11-01.html • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-6716
https://notcve.org/view.php?id=CVE-2016-6716
An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission). Android ID: A-30778130. Una vulnerabilidad de elevación de privilegio en el AOSP Launcher en Android 7.0 en versiones anteriores a 01-11-2016 podría permitir a una aplicación maliciosa local crear atajos que tienen privilegios elevados sin el consentimiento del usuario. Este problema está clasificado como Moderate porque es una elusión local de los requerimientos de interacción de usuario (acceso a funcionalidad que normalmente requiere o bien iniciación de usuario o bien permiso de usuario). • http://www.securityfocus.com/bid/94171 https://source.android.com/security/bulletin/2016-11-01.html • CWE-284: Improper Access Control •
CVE-2016-3907
https://notcve.org/view.php?id=CVE-2016-3907
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30593266. References: Qualcomm QC-CR#1054352. Una vulnerabilidad de divulgación de información en componentes Qualcomm incluyendo el controlador de la GPU, controlador de energía, controlador SMSM Point-to-Point y controlador de sonido en Android en versiones anteriores a 05-11-2016 podría habilitar a una aplicación local maliciosa a acceder a datos fuera de sus niveles de permiso. • http://www.securityfocus.com/bid/94139 https://source.android.com/security/bulletin/2016-11-01.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •