
CVE-2016-6753
https://notcve.org/view.php?id=CVE-2016-6753
25 Nov 2016 — An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30149174. Una vulnerabilidad de divulgación de información en componentes del kernel, incluidos el subsistema process-grouping y el subsistema networki... • http://www.securityfocus.com/bid/94147 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-6754 – Google Android - 'BadKernel' Remote Code Execution
https://notcve.org/view.php?id=CVE-2016-6754
25 Nov 2016 — A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937. Una vulnerabilidad de ejecución de código remoto en Webview en Android 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en ve... • https://www.exploit-db.com/exploits/40846 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2016-3904
https://notcve.org/view.php?id=CVE-2016-3904
25 Nov 2016 — An elevation of privilege vulnerability in the Qualcomm bus driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30311977. References: Qualcomm QC-CR#1050455. Una vulnerabilidad de elevación de privilegio en el controlador bus de Qualcomm en Android en versiones anteriores a 05-11-2016 podría habilitar una aplicación loca... • http://www.securityfocus.com/bid/94210 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-3906
https://notcve.org/view.php?id=CVE-2016-3906
25 Nov 2016 — An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30445973. References: Qualcomm QC-CR#1054344. Una vulnerabilidad de divulgación de información en componentes Qualcomm incluyendo el con... • http://www.securityfocus.com/bid/94139 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3907
https://notcve.org/view.php?id=CVE-2016-3907
25 Nov 2016 — An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30593266. References: Qualcomm QC-CR#1054352. Una vulnerabilidad de divulgación de información en componentes Qualcomm incluyendo el con... • http://www.securityfocus.com/bid/94139 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3932
https://notcve.org/view.php?id=CVE-2016-3932
10 Oct 2016 — mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTek internal bug ALPS02770870. mediaserver en Android en versiones anteriores a 2016-10-05 permite a atacantes obtener privilegios a través de una aplicación manipulada, vulnerabilidad también conocida como error interno de Android 29161895 y error interno de MediaTek ALPS02770870. • http://source.android.com/security/bulletin/2016-10-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-3933
https://notcve.org/view.php?id=CVE-2016-3933
10 Oct 2016 — mediaserver in Android before 2016-10-05 on Nexus 9 and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 29421408. mediaserver en Android en versiones anteriores a 2016-10-05 en dispositivos Nexus 9 y Pixel C permite a atacantes obtener privilegios a través de una aplicación manipulada, vulnerabilidad también conocida como error interno 29421408. • http://source.android.com/security/bulletin/2016-10-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-3940
https://notcve.org/view.php?id=CVE-2016-3940
10 Oct 2016 — The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 6P and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 30141991. El controlador de pantalla táctil Synaptics en Android en versiones anteriores a 2016-10-05 en dispositivos Nexus 6P y Android One permite a atacantes obtener privilegios a través de una aplicación manipulada, vulnerabilidad también conocida como error interno 30141991. • http://source.android.com/security/bulletin/2016-10-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-3901
https://notcve.org/view.php?id=CVE-2016-3901
10 Oct 2016 — Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29999161 and Qualcomm internal bug CR 1046434. Múltiples desbordamientos de enteros en drivers/crypto/msm/qcedev.c en el controlador de motor criptográfico de Qualcomm en Android en versiones anteriores a 2016-10-05 en dispositivos Nexus ... • http://source.android.com/security/bulletin/2016-10-01.html • CWE-190: Integer Overflow or Wraparound •

CVE-2016-6672
https://notcve.org/view.php?id=CVE-2016-6672
10 Oct 2016 — The Synaptics touchscreen driver in Android before 2016-10-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka internal bug 30537088. El controlador de pantalla táctil Synaptics en Android en versiones anteriores a 2016-10-05 en dispositivos Nexus 5X permite a atacantes obtener privilegios a través de una aplicación manipulada, vulnerabilidad también conocida como error interno 30537088. • http://source.android.com/security/bulletin/2016-10-01.html • CWE-264: Permissions, Privileges, and Access Controls •