CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,293 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,585 researchers
110,849 results Clear all
CVE-2016-5400 4.3 MEDIUM EPSS 0.00
Linux Kernel < 4.6.6 - Memory Corruption
Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.
CWE-119 Aug 06, 2016
CVE-2015-8944 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devices, uses weak permissions for /proc/iomem, which allows local users to obtain sensitive information by reading this file, aka Android internal bug 28814213 and Qualcomm internal bug CR786116. NOTE: the permissions may be intentional in most non-Android contexts.
CWE-200 Aug 06, 2016
CVE-2014-9900 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not initialize a certain data structure, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28803952 and Qualcomm internal bug CR570754.
CWE-200 Aug 06, 2016
CVE-2014-9899 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
drivers/usb/host/ehci-msm2.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices omits certain minimum calculations before copying data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28803909 and Qualcomm internal bug CR547910.
CWE-200 Aug 06, 2016
CVE-2014-9898 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate input parameters, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28814690 and Qualcomm internal bug CR554575.
CWE-200 Aug 06, 2016
CVE-2014-9897 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate certain user-space data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28769856 and Qualcomm internal bug CR563752.
CWE-200 Aug 06, 2016
CVE-2014-9896 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
drivers/char/adsprpc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate parameters and return values, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28767593 and Qualcomm internal bug CR551795.
CWE-200 Aug 06, 2016
CVE-2014-9895 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize certain data structures, which allows local users to obtain sensitive information via a crafted application, aka Android internal bug 28750150 and Qualcomm internal bug CR570757, a different vulnerability than CVE-2014-1739.
CWE-200 Aug 06, 2016
CVE-2014-9894 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not ensure that certain name strings end in a '\0' character, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28749708 and Qualcomm internal bug CR545736.
CWE-200 Aug 06, 2016
CVE-2014-9893 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not properly determine the size of Gamut LUT data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28747914 and Qualcomm internal bug CR542223.
CWE-200 Aug 06, 2016
CVE-2014-9892 5.5 MEDIUM EPSS 0.00
Google Android < 6.0.1 - Information Disclosure
The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28770164 and Qualcomm internal bug CR568717.
CWE-200 Aug 06, 2016
CVE-2016-3853 5.5 MEDIUM EPSS 0.00
Google Play services <2016-08-05 - Info Disclosure
Google Play services in Android before 2016-08-05 on Nexus devices allow local users to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26803208.
CWE-264 Aug 05, 2016
CVE-2016-3852 5.5 MEDIUM EPSS 0.00
MediaTek Wi-Fi driver - Info Disclosure
The MediaTek Wi-Fi driver in Android before 2016-08-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29141147 and MediaTek internal bug ALPS02751738.
CWE-200 Aug 05, 2016
CVE-2016-3839 5.5 MEDIUM EPSS 0.00
Android <4.4.4, <5.0.2, <5.1.1, <2016-08-01 - DoS
Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a crafted application that sends a signal to a Bluetooth process, aka internal bug 28885210.
CWE-284 Aug 05, 2016
CVE-2016-3838 5.5 MEDIUM EPSS 0.00
Android <6 - DoS
Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that uses the app-pinning feature, aka internal bug 28761672.
CWE-284 Aug 05, 2016
CVE-2016-3837 5.5 MEDIUM EPSS 0.00
Android <5.0.2, <5.1.1, <2016-08-01 - Info Disclosure
service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application that provides a MAC address with too few characters, aka internal bug 28164077.
CWE-200 Aug 05, 2016
CVE-2016-3836 5.5 MEDIUM EPSS 0.00
Android <5.0.2, <5.1.1, <2016-08-01 - Info Disclosure
The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka internal bug 28592402.
CWE-200 Aug 05, 2016
CVE-2016-3835 5.5 MEDIUM EPSS 0.00
Android <4.4.4, <5.0.2, <5.1.1, <2016-08-01 - Info Disclosure
The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 28920116.
CWE-200 Aug 05, 2016
CVE-2016-3834 5.5 MEDIUM EPSS 0.00
Android <4.4.4, <5.0.2, <5.1.1, <2016-08-01 - Auth Bypass
The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended access restrictions and obtain sensitive information about ANW buffer addresses via a crafted application, aka internal bug 28466701.
CWE-200 Aug 05, 2016
CVE-2016-3830 5.5 MEDIUM EPSS 0.00
Android <4.4.4, <5.0.2, <5.1.1, <2016-08-01 - DoS
codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cause a denial of service (device hang or reboot) via crafted ADTS data, aka internal bug 29153599.
CWE-20 Aug 05, 2016