LiveActive security incident?Get immediate response
CVE archive

January 2016

Browse CVE records published in January 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1112 matching CVEs · Page 11 of 23.

Unknown · CVSS Not scored

CVE-2016-6785: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application t...

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31748056. References: MT-ALPS02961400.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6775: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application...

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-31222873. References: N-CVE-2016-6775.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6771: An elevation of privilege vulnerability in Telephony could enable a local malicious application to access s...

An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-31566390.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6763: A denial of service vulnerability in Telephony could enable a local malicious application to use a speciall...

A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of local permanent denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31530456.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6755: An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious applic...

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-30740545. References: QC-CR#1065916.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6788: An elevation of privilege vulnerability in the MediaTek I2C driver could enable a local malicious applicati...

An elevation of privilege vulnerability in the MediaTek I2C driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31224428. References: MT-ALPS02943467.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6772: An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbi...

An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31856351.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6781: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application t...

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31095175. References: MT-ALPS02943455.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6759: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application...

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29982686. References: QC-CR#1055766.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6784: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application t...

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31350755. References: MT-ALPS02961424.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6761: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application...

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29421682. References: QC-CR#1055792.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6756: An information disclosure vulnerability in Qualcomm components including the camera driver and video driver...

An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29464815. References: QC-CR#1042068.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6774: An information disclosure vulnerability in Package Manager could enable a local malicious application to by...

An information disclosure vulnerability in Package Manager could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: 7.0. Android ID: A-31251489.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6762: An elevation of privilege vulnerability in the libziparchive library could enable a local malicious applica...

An elevation of privilege vulnerability in the libziparchive library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31251826.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6769: An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart L...

An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Smart Lock was the last settings pane accessed by the user. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-29055171.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6766: A denial of service vulnerability in libmedia and libstagefright in Mediaserver could enable an attacker to...

A denial of service vulnerability in libmedia and libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31318219.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6783: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application t...

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31350044. References: MT-ALPS02943437.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6760: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application...

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29617572. References: QC-CR#1055783.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6765: A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specia...

A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 7.0. Android ID: A-31449945.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6777: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application...

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-31910462. References: N-CVE-2016-6777.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6770: An elevation of privilege vulnerability in the Framework API could enable a local malicious application to...

An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-30202228.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6758: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application...

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-30148882. References: QC-CR#1071731.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6778: An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious applic...

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31384646.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6790: An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malici...

An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.18. Android ID: A-31251628. References: N-CVE-2016-6790.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6668: The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, an...

The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to obtain the secret key for communicating with HipChat instances by reading unspecified pages.

Published Jan 23, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6599: BMC Track-It!

BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that contains the application database name, username and password as well as the domain administrator username and password. These are encrypted with a fixed key and IV ("NumaraIT") using the DES algorithm. The domain administrator username and password can only be obtained if the Self-Service component is enabled, which is the most common scenario in enterprise deployments.

Published Jan 30, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6590: A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Mana...

A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.

Published Jan 8, 2020 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6592: A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6.

A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code when the Norton Download Manager component is run by the target user.

Published Jan 14, 2020 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6581: A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could...

A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called "HPACK Bomb" attack. This attack occurs when an attacker inserts a header field that is exactly the size of the HPACK dynamic header table into the dynamic header table. The attacker can then send a header block that is simply repeated requests to expand that field in the dynamic table. This can lead to a gigantic compression ratio of 4,096 or better, meaning that 16kB of data can decompress to 64MB of data on the target machine.

Published Jan 10, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6595: The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prev...

The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this sequence is not "removing the state that is left by old nodes. At some point the manager obviously stops being able to accept new nodes, since it runs out of memory. Given that both for Docker swarm and for Docker Swarmkit nodes are *required* to provide a secret token (it's actually the only mode of operation), this means that no adversary can simply join nodes and exhaust manager resources. We can't do anything about a manager running out of memory and not being able to add new legitimate nodes to the system. This is merely a resource provisioning issue, and definitely not a CVE worthy vulnerability.

Published Jan 4, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6598: BMC Track-It!

BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.

Published Jan 30, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6580: A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could...

A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually use a tree like this would also cause extremely high CPU usage to maintain the tree.

Published Jan 10, 2017 · Updated Aug 6, 2024