CVE-2016-3745
published 2016-07-11CVE-2016-3745: Multiple buffer overflows in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain…
PriorityP339critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.58%
44.4th percentile
Multiple buffer overflows in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides an AudioEffect reply, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28173666.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-3745: Android Security Bulletin 2016-07-01
CVE: CVE-2016-3745
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-07-01·CVSS 9.8
CVE-2016-3745 [CRITICAL] CVE-2016-3745: Android Security Bulletin 2016-07-01
CVE: CVE-2016-3745
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-07-01
CVE: CVE-2016-3745
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1
References: A-28173666
GHSA
GHSA-p9p6-6j8g-pfm7: Multiple buffer overflows in mediaserver in Android 4
ghsa_unreviewed·2022-05-17
CVE-2016-3745 [CRITICAL] CWE-119 GHSA-p9p6-6j8g-pfm7: Multiple buffer overflows in mediaserver in Android 4
Multiple buffer overflows in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides an AudioEffect reply, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28173666.
OSV
CVE-2016-3745: Multiple buffer overflows in mediaserver in Android 4
osv·2016-07-11·CVSS 9.8
CVE-2016-3745 [CRITICAL] CVE-2016-3745: Multiple buffer overflows in mediaserver in Android 4
Multiple buffer overflows in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allow attackers to gain privileges via a crafted application that provides an AudioEffect reply, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28173666.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-07-01.htmlhttps://android.googlesource.com/platform/hardware/qcom/audio/+/073a80800f341325932c66818ce4302b312909a4http://source.android.com/security/bulletin/2016-07-01.htmlhttps://android.googlesource.com/platform/hardware/qcom/audio/+/073a80800f341325932c66818ce4302b312909a4
2016-07-11
Published