
CVE-2016-3888
https://notcve.org/view.php?id=CVE-2016-3888
11 Sep 2016 — internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS messages during the Setup Wizard provisioning stage, via unspecified vectors, aka internal bug 29420123. internal/telephony/SMSDispatcher.java en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x ... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-3890
https://notcve.org/view.php?id=CVE-2016-3890
11 Sep 2016 — The Java Debug Wire Protocol (JDWP) implementation in adb/sockets.cpp in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 mishandles socket close operations, which allows attackers to gain privileges via a crafted application, aka internal bug 28347842. La implementación del Java Debug Wire Protocol (JDWP) en adb/sockets.cpp en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versione... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-3892
https://notcve.org/view.php?id=CVE-2016-3892
11 Sep 2016 — The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28760543 and Qualcomm internal bug CR1024197. El controlador Qualcomm SPMI en Android en versiones anteriores a 2016-09-05 en dispositivos Nexus 5, 5X, 6 y 6P permite a atacantes obtener información sensible a través de una aplicación manipulada, vulnerabilidad también conocida como error interno de Android 28760543 y err... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3893
https://notcve.org/view.php?id=CVE-2016-3893
11 Sep 2016 — The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before 2016-09-05 on Nexus 6P devices does not properly copy firmware data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29512527 and Qualcomm internal bug CR856400. La función wcdcal_hwdep_ioctl_shared en sound/soc/codecs/wcdcal-hwdep.c en el códec de sonido Qualcomm en Android en versiones anteriores a 2016-09-05 en dispositivos Nexu... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3894
https://notcve.org/view.php?id=CVE-2016-3894
11 Sep 2016 — The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29618014 and Qualcomm internal bug CR1042033. El componente DMA Qualcomm en Android en versiones anteriores a 2016-09-05 en dispositivos Nexus 6 permite a atacantes obtener información sensible a través de una aplicación manipulada, vulnerabilidad también conocida como error interno de Android 29618014 y error interno de Qualcomm CR10... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3896
https://notcve.org/view.php?id=CVE-2016-3896
11 Sep 2016 — AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows attackers to obtain sensitive EmailAccountCacheProvider information via a crafted application, aka internal bug 29767043. AOSP Mail en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1 y 6.x en versiones anteriores a 2016-09-01 permite a atacantes obtener información sensible de EmailAccountCacheProvider a través de una aplica... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3897
https://notcve.org/view.php?id=CVE-2016-3897
11 Sep 2016 — The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 includes a password in the return value of a toString method call, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 25624963. La clase WifiEnterpriseConfig en net/wifi/WifiEnterpriseConfig.java en Wi-Fi en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2,... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-3898
https://notcve.org/view.php?id=CVE-2016-3898
11 Sep 2016 — Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to cause a denial of service (loss of locked-screen 911 TTY functionality) via a crafted application that modifies the TTY mode by broadcasting an intent, aka internal bug 29832693. Telephony en Android 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1, 6.x en versiones anteriores a 2016-09-01 y 7.0 en versiones anteriores a 2016-09-01 permite a atacantes ... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-284: Improper Access Control •

CVE-2016-3899
https://notcve.org/view.php?id=CVE-2016-3899
11 Sep 2016 — OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not validate a certain pointer, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29421811. OMXCodec.cpp en libstagefright en mediaserver en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1, 6.x... • http://source.android.com/security/bulletin/2016-09-01.html • CWE-284: Improper Access Control •

CVE-2016-3861 – Google Android - libutils UTF16 to UTF8 Conversion Heap Buffer Overflow
https://notcve.org/view.php?id=CVE-2016-3861
08 Sep 2016 — LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted file, aka internal bug 29250543. LibUtils en Android 4.x en versiones anteriores a 4.4.4, 5.0.x en versiones anteriores a 5.0.2, 5.1.x en versiones anteriores a 5.1.1... • https://packetstorm.news/files/id/138624 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-264: Permissions, Privileges, and Access Controls •