CVE-2016-2567

Severity
3.3LOW
EPSS
0.1%
top 76.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 17

Description

secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the http://should-have-been-filtered.example.com/?http://google.com URL.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDsamsung/galaxy_s6_firmwareg920fxxu2coh2

🔴Vulnerability Details

2
GHSA
GHSA-mgxj-2m8w-mj9x: secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attac2022-05-17
CVEList
CVE-2016-2567: secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attac2017-04-13

💬Community

1
Bugzilla
CVE-2016-3619 libtiff: bmp2tiff DumpModeEncode OOB read2016-03-10
CVE-2016-2567 (LOW CVSS 3.3) | secfilter in the Samsung kernel for | cvebase.io