CVE-2016-0802
published 2016-02-07CVE-2016-0802: The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute…
PriorityP346high8.8CVSS 3.0
AVAACLPRNUINSUCHIHAH
EPSS
1.70%
74.6th percentile
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| apple | tvos | <= 9.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.1 | — |
| apple | watchos | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-0802: Android Security Bulletin 2016-02-01
CVE: CVE-2016-0802
Severity: CRITICAL
Affected AOSP versions: 4
vendor_android·2016-02-01·CVSS 8.8
CVE-2016-0802 [HIGH] CVE-2016-0802: Android Security Bulletin 2016-02-01
CVE: CVE-2016-0802
Severity: CRITICAL
Affected AOSP versions: 4
Android Security Bulletin 2016-02-01
CVE: CVE-2016-0802
Severity: CRITICAL
Affected AOSP versions: 4.4.4, 5.0, 5.1.1, 6.0, 6.0.1
Apple
CVE-2016-0802: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 8.8
CVE-2016-0802 [HIGH] CVE-2016-0802: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2016-0802
Component: CVE-ID
Apple
CVE-2016-0802: tvOS 9.2
vendor_apple·CVSS 8.8
CVE-2016-0802 [HIGH] CVE-2016-0802: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2016-0802
Component: CVE-ID
Apple
CVE-2016-0802: iOS 9.3
vendor_apple·CVSS 8.8
CVE-2016-0802 [HIGH] CVE-2016-0802: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-0802
Component: CVE-ID
Apple
CVE-2016-0802: watchOS 2.2
vendor_apple·CVSS 8.8
CVE-2016-0802 [HIGH] CVE-2016-0802: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2016-0802
Component: CVE-ID
GHSA
GHSA-qphj-43q8-79g3: The Broadcom Wi-Fi driver in the kernel in Android 4
ghsa_unreviewed·2022-05-14
CVE-2016-0802 [HIGH] CWE-20 GHSA-qphj-43q8-79g3: The Broadcom Wi-Fi driver in the kernel in Android 4
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
OSV
CVE-2016-0802: The Broadcom Wi-Fi driver in the kernel in Android 4
osv·2016-02-07·CVSS 8.8
CVE-2016-0802 [HIGH] CVE-2016-0802: The Broadcom Wi-Fi driver in the kernel in Android 4
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://source.android.com/security/bulletin/2016-02-01.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-004.txthttp://www.securitytracker.com/id/1035353https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://source.android.com/security/bulletin/2016-02-01.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-004.txthttp://www.securitytracker.com/id/1035353https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169
2016-02-07
Published