CVE-2016-0824
published 2016-03-12CVE-2016-0824: libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection…
PriorityP423medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
0.65%
47.6th percentile
libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25765591.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | >= 0 < 20160307-0742-0ubuntu3 | 20160307-0742-0ubuntu3 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxw6-wm7v-4qx6: libmpeg2 in libstagefright in Android 6
ghsa_unreviewed·2022-05-17
CVE-2016-0824 [MEDIUM] CWE-200 GHSA-vxw6-wm7v-4qx6: libmpeg2 in libstagefright in Android 6
libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25765591.
OSV
CVE-2016-0824: libmpeg2 in libstagefright in Android 6
osv·2016-03-12·CVSS 5.3
CVE-2016-0824 [MEDIUM] CVE-2016-0824: libmpeg2 in libstagefright in Android 6
libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25765591.
Android
CVE-2016-0824: Android Security Bulletin 2016-03-01
CVE: CVE-2016-0824
Severity: HIGH
Affected AOSP versions: 6
vendor_android·2016-03-01·CVSS 5.3
CVE-2016-0824 [MEDIUM] CVE-2016-0824: Android Security Bulletin 2016-03-01
CVE: CVE-2016-0824
Severity: HIGH
Affected AOSP versions: 6
Android Security Bulletin 2016-03-01
CVE: CVE-2016-0824
Severity: HIGH
Affected AOSP versions: 6.0, 6.0.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.securityfocus.com/bid/84262https://android.googlesource.com/platform/external/libmpeg2/+/ffab15eb80630dc799eb410855c93525b75233c3http://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.securityfocus.com/bid/84262https://android.googlesource.com/platform/external/libmpeg2/+/ffab15eb80630dc799eb410855c93525b75233c3
2016-03-12
Published