peter bassill · operator
$ cve CVE-2016-2417 JSON

CVE-2016-2417 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 5.3% (pctl 92)

Patch early

A public exploit exists.

Description

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.32% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2016-04-18
Last modified2026-06-17

Affected (1)

VendorProduct
googleandroid

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD