CVE-2016-2464
published 2016-06-13CVE-2016-2464: libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to…
PriorityP338high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.75%
75.4th percentile
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvpx | < libvpx 1.6.1-1 (bookworm) | libvpx 1.6.1-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| webmproject | libvpx | >= 0 < 1.6.1-1 | 1.6.1-1 |
| webmproject | libvpx | >= 0 < 1.6.1-1 | 1.6.1-1 |
| webmproject | libvpx | >= 0 < 1.6.1-1 | 1.6.1-1 |
| webmproject | libvpx | >= 0 < 1.6.1-1 | 1.6.1-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rmww-hg8j-xpw9: libvpx in libwebm in mediaserver in Android 4
ghsa_unreviewed·2022-05-17
CVE-2016-2464 [HIGH] CWE-20 GHSA-rmww-hg8j-xpw9: libvpx in libwebm in mediaserver in Android 4
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
OSV
CVE-2016-2464: libvpx in libwebm in mediaserver in Android 4
osv·2016-06-13·CVSS 7.8
CVE-2016-2464 [HIGH] CVE-2016-2464: libvpx in libwebm in mediaserver in Android 4
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
Android
CVE-2016-2464: Android Security Bulletin 2016-06-01
CVE: CVE-2016-2464
Severity: CRITICAL
Affected AOSP versions: 4
vendor_android·2016-06-01·CVSS 7.8
CVE-2016-2464 [HIGH] CVE-2016-2464: Android Security Bulletin 2016-06-01
CVE: CVE-2016-2464
Severity: CRITICAL
Affected AOSP versions: 4
Android Security Bulletin 2016-06-01
CVE: CVE-2016-2464
Severity: CRITICAL
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1
Debian
CVE-2016-2464: libvpx - libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2...
vendor_debian·2016·CVSS 7.8
CVE-2016-2464 [HIGH] CVE-2016-2464: libvpx - libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2...
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-06-01.htmlhttps://android.googlesource.com/platform/external/libvpx/+/65c49d5b382de4085ee5668732bcb0f6ecaf7148https://android.googlesource.com/platform/external/libvpx/+/cc274e2abe8b2a6698a5c47d8aa4bb45f1f9538dhttp://source.android.com/security/bulletin/2016-06-01.htmlhttps://android.googlesource.com/platform/external/libvpx/+/65c49d5b382de4085ee5668732bcb0f6ecaf7148https://android.googlesource.com/platform/external/libvpx/+/cc274e2abe8b2a6698a5c47d8aa4bb45f1f9538d
2016-06-13
Published