CVE-2016-10277 – Motorola Bootloader - Kernel Cmdline Injection Secure Boot and Device Locking Bypass
https://notcve.org/view.php?id=CVE-2016-10277
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33840490. • https://www.exploit-db.com/exploits/42601 http://www.securityfocus.com/bid/98149 https://source.android.com/security/bulletin/2017-05-01 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-10283
https://notcve.org/view.php?id=CVE-2016-10283
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32094986. • http://www.securityfocus.com/bid/98160 https://source.android.com/security/bulletin/2017-05-01 https://www.codeaurora.org/stack-overflow-wifi-driver-function-wlanhddchangestation-cve-2016-10283 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2017-0627
https://notcve.org/view.php?id=CVE-2017-0627
An information disclosure vulnerability in the kernel UVC driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33300353. • http://www.securityfocus.com/bid/98205 https://source.android.com/security/bulletin/2017-05-01 https://usn.ubuntu.com/3674-1 https://usn.ubuntu.com/3674-2 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-0634
https://notcve.org/view.php?id=CVE-2017-0634
An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32511682. • http://www.securityfocus.com/bid/98224 https://source.android.com/security/bulletin/2017-05-01 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-0614
https://notcve.org/view.php?id=CVE-2017-0614
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-35399405. • http://www.securityfocus.com/bid/98187 https://source.android.com/security/bulletin/2017-05-01 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •