cbcvebase.
CVE-2016-3809
published 2016-07-11

CVE-2016-3809: The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C…

PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.35%
27.9th percentile
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.

Affected

3 ranges
VendorProductVersion rangeFixed in
googleandroid<= 6.0.1
googleandroid
openbsdopenssh>= 0 < 1:7.6p1-4ubuntu0.51:7.6p1-4ubuntu0.5

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.