Page 38 of 979 results (0.020 seconds)

CVSS: 8.8EPSS: 2%CPEs: 6EXPL: 2

25 Nov 2016 — A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937. Una vulnerabilidad de ejecución de código remoto en Webview en Android 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en ve... • https://www.exploit-db.com/exploits/40846 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

25 Nov 2016 — An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30902162. References: Qualcomm QC-CR#1062271. Una vulnerabilidad de divulgación de información en componentes Qualcomm incluidos el cont... • http://www.securityfocus.com/bid/94139 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

25 Nov 2016 — An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypass of user interaction requirements for any developer or security setting modifications. Android ID: A-30693465. Una elevación de privilegio en el System UI en Android 7.0 en versiones anteriores a 01-11-2016 podría habilitar a un usuario local malicioso a eludir el aviso ... • http://www.securityfocus.com/bid/94166 • CWE-254: 7PK - Security Features CWE-284: Improper Access Control •

CVSS: 9.3EPSS: 0%CPEs: 20EXPL: 0

25 Nov 2016 — An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30916186. Una vulnerabilidad de elevación de privilegios en libzipfile en Android 4.x en ver... • http://www.securityfocus.com/bid/94159 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

25 Nov 2016 — An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30904789. References: NVIDIA N-CVE-2016-6730. Una vulnerabilidad de elevación de privilegio en el controlador de la GPU en Android en ... • http://www.securityfocus.com/bid/94140 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

25 Nov 2016 — An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Android ID: A-30955105. References: NVIDIA N-CVE-2016-6746. Una vulnerabilidad de divulgación de información en el controlador NVIDIA GPU en Android en versiones anteriores a 05-11-2016 podría habilitar a una aplic... • http://www.securityfocus.com/bid/94209 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

25 Nov 2016 — An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30906023. References: NVIDIA N-CVE-2016-6731. Una vulnerabilidad de elevación de privilegio en el controlador NVIDIA GPU en Android en... • http://www.securityfocus.com/bid/94140 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.3EPSS: 0%CPEs: 2EXPL: 0

25 Nov 2016 — An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30143904. References: Qualcomm QC-CR#1056307. Una vulnerabilidad de elevación de privilegio en el controlador de cámara Qualcomm en Android en versiones anteriores a 05-11-2016 podría habilitar a una aplicac... • http://www.securityfocus.com/bid/94142 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.1EPSS: 0%CPEs: 5EXPL: 0

25 Nov 2016 — A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to cause the device to continually reboot. This issue is rated as Moderate because it is a temporary denial of service that requires a factory reset to fix. Android ID: A-30568284. Una vulnerabilidad de denegación de servicio en el Input Manager Service en Android 4.x en versiones anteri... • http://www.securityfocus.com/bid/94180 • CWE-284: Improper Access Control •

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

25 Nov 2016 — An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30937462. Una vulnerabilidad de elevación de privilegio en el controlador de pantalla táctil Synaptics en Android en versiones anteriores a 05-11-2016 podría habilitar a una aplicación maliciosa local ... • http://www.securityfocus.com/bid/94131 • CWE-264: Permissions, Privileges, and Access Controls •