
CVE-2016-6701
https://notcve.org/view.php?id=CVE-2016-6701
25 Nov 2016 — A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637. Una vulnerabilidad de ejecución remota de código en libskia en Android 7.0 en versiones anteriores a 01-11-2016 podría habilitar a un atacante que utiliza un archivo... • http://www.securityfocus.com/bid/94162 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-284: Improper Access Control •

CVE-2016-6702
https://notcve.org/view.php?id=CVE-2016-6702
25 Nov 2016 — A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087. Una vulnerabilidad de ejecución remota de código en libjpeg en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones an... • http://www.securityfocus.com/bid/94160 • CWE-284: Improper Access Control •

CVE-2016-6703
https://notcve.org/view.php?id=CVE-2016-6703
25 Nov 2016 — A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker using a specially crafted payload to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Android runtime. Android ID: A-30765246. Una vulnerabilidad de ejecución de código remoto en la biblioteca Androi... • http://www.securityfocus.com/bid/94161 • CWE-284: Improper Access Control •

CVE-2016-6704
https://notcve.org/view.php?id=CVE-2016-6704
25 Nov 2016 — An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-30229821. Una vulnerabilidad de elevación de pri... • http://www.securityfocus.com/bid/94134 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-6705
https://notcve.org/view.php?id=CVE-2016-6705
25 Nov 2016 — An elevation of privilege vulnerability in Mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-30907212. Una vulnerabilidad de elevación de privilegio en Mediase... • http://www.securityfocus.com/bid/94134 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-6708
https://notcve.org/view.php?id=CVE-2016-6708
25 Nov 2016 — An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypass of user interaction requirements for any developer or security setting modifications. Android ID: A-30693465. Una elevación de privilegio en el System UI en Android 7.0 en versiones anteriores a 01-11-2016 podría habilitar a un usuario local malicioso a eludir el aviso ... • http://www.securityfocus.com/bid/94166 • CWE-254: 7PK - Security Features CWE-284: Improper Access Control •

CVE-2016-6710
https://notcve.org/view.php?id=CVE-2016-6710
25 Nov 2016 — An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Android ID: A-30537115. Una vulnerabilidad de divulgación de información en el gestor de ... • http://www.securityfocus.com/bid/94170 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-6715
https://notcve.org/view.php?id=CVE-2016-6715
25 Nov 2016 — An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio without the user's permission. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission.) Android ID: A-29833954. Una vulnerabilidad de elevac... • http://www.securityfocus.com/bid/94173 • CWE-275: Permission Issues CWE-284: Improper Access Control •

CVE-2016-6716
https://notcve.org/view.php?id=CVE-2016-6716
25 Nov 2016 — An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission). Android ID: A-30778130. Una vulnerabilidad de elevación de privilegio en el AOSP Launcher en Android 7.0 en... • http://www.securityfocus.com/bid/94171 • CWE-284: Improper Access Control •

CVE-2016-6717 – Android Mitigation Bypass
https://notcve.org/view.php?id=CVE-2016-6717
25 Nov 2016 — An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability. Android ID: A-31350239. Una vulnerabilidad de elevación de privilegio en Mediaserver en Android 4.x en versiones anteriores a ... • http://www.securityfocus.com/bid/94178 • CWE-264: Permissions, Privileges, and Access Controls •