CVE-2016-0802Improper Input Validation in Apple OS X EL Capitan V10.11.4 AND Security Update 2016-002

Severity
8.8HIGHNVD
EPSS
6.7%
top 8.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7
Latest updateMay 14

Description

The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages10 packages

🔴Vulnerability Details

2
GHSA
GHSA-qphj-43q8-79g3: The Broadcom Wi-Fi driver in the kernel in Android 42022-05-14
OSV
CVE-2016-0802: The Broadcom Wi-Fi driver in the kernel in Android 42016-02-07

📋Vendor Advisories

5
Android
CVE-2016-0802: Android Security Bulletin 2016-02-01 CVE: CVE-2016-0802 Severity: CRITICAL Affected AOSP versions: 42016-02-01
Apple
CVE-2016-0802: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple
CVE-2016-0802: tvOS 9.2
Apple
CVE-2016-0802: iOS 9.3
Apple
CVE-2016-0802: watchOS 2.2