Page 29 of 1217 results (0.008 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Aug 2017 — A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392. • http://www.securityfocus.com/bid/100213 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Aug 2017 — A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel. Android ID: A-32524214. References: QC-CR#2044821. • http://www.securityfocus.com/bid/100213 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Aug 2017 — A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735. Existe una vulnerabilidad de elevación de privilegios en el kernel linux en Upstream Linux. • http://www.securityfocus.com/bid/100215 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Aug 2017 — A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013. Existe una vulnerabilidad de elevación de privilegios en el sistema de archivos Upstream Linux. • http://www.securityfocus.com/bid/100215 • CWE-787: Out-of-bounds Write •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

07 Aug 2017 — The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash). La función updateMessageStatus en Android 5.1.1 y anteriores permite que usuarios locales provoquen una denegación de servicio (excepción de puntero nulo y caída de procesos). • https://github.com/mabin004/cve-2015-3839_PoC • CWE-476: NULL Pointer Dereference •

CVSS: 5.9EPSS: 0%CPEs: 4EXPL: 0

02 Aug 2017 — The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version 2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. Las versiones 2.0.3 y anteriores de la aplicación RBB SPEED TEST App para Android, así como las versiones 2.1.0 y anteriores para iOS no verifican certificados X.509 desde servidores SSL. Esto permite a los atacantes que reali... • http://www.iid.co.jp/information/170714.html • CWE-295: Improper Certificate Validation •

CVSS: 7.6EPSS: 0%CPEs: 1EXPL: 0

13 Jul 2017 — An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34373711. • http://www.securityfocus.com/bid/99616 •

CVSS: 7.0EPSS: 0%CPEs: 1EXPL: 0

07 Jul 2017 — Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found should execute bindBackupAgent with the uid member of the ApplicationInfo parameter set to 1000. Condición de carrera en el método bindBackupAgent en el ActivityM... • http://seclists.org/fulldisclosure/2015/Apr/52 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 9.3EPSS: 0%CPEs: 7EXPL: 0

06 Jul 2017 — A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36491278. Una vulnerabilidad de elevación de privilegios en el Android framework. • http://www.securityfocus.com/bid/99470 •

CVSS: 9.3EPSS: 0%CPEs: 8EXPL: 0

06 Jul 2017 — A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36991414. Una vulnerabilidad de elevación de privilegios en Android. • http://www.securityfocus.com/bid/99470 • CWE-20: Improper Input Validation •