CVE-2016-3809
published 2016-07-11CVE-2016-3809: The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.35%
27.9th percentile
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 6.0.1 | — | |
| android | — | — | |
| openbsd | openssh | >= 0 < 1:7.6p1-4ubuntu0.5 | 1:7.6p1-4ubuntu0.5 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-58vv-xv4c-fj42: The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and
ghsa_unreviewed·2022-05-17
CVE-2016-3809 [MEDIUM] CWE-200 GHSA-58vv-xv4c-fj42: The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.
OSV
openssh regression
osv·2021-08-12·CVSS 7.5
CVE-2018-15473 openssh regression
openssh regression
USN-3809-1 fixed vulnerabilities in OpenSSH. The update for CVE-2018-15473
was incomplete and could introduce a regression in certain environments.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Robert Swiecki discovered that OpenSSH incorrectly handled certain messages.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-10708)
It was discovered that OpenSSH incorrectly handled certain requests.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-15473)
Project0
In-the-Wild Series: Android Exploits - Project Zero
project_zero·2021-01-01·CVSS 7.8
CVE-2015-0569 [HIGH] In-the-Wild Series: Android Exploits - Project Zero
This is part 4 of a 6-part series detailing a set of vulnerabilities found by Project Zero being exploited in the wild. To read the other parts of the series, see the introduction post.
Posted by Mark Brand, Project Zero
A survey of the exploitation techniques used by a high-tier attacker against Android devices in 2020
## Introduction
After one of the Chrome exploits has been successful, there are several (quite simple) stages of payload decryption that occur. Once we've got through that, we reach a much more complex binary that is clearly the result of some engineering work. Thanks to that engineering it's very simple for us to locate and examine the exploits embedded inside! For each privilege elevation, they have a function in the .init_array which will register it into a global
OSV
CVE-2016-3809: The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and
osv·2016-07-11·CVSS 5.5
CVE-2016-3809 [MEDIUM] CVE-2016-3809: The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and
The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 27532522.
Android
CVE-2016-3809: Android Security Bulletin 2016-07-01
CVE: CVE-2016-3809
Severity: HIGH
References: A-27532522*
vendor_android·2016-07-01·CVSS 5.5
CVE-2016-3809 [MEDIUM] CVE-2016-3809: Android Security Bulletin 2016-07-01
CVE: CVE-2016-3809
Severity: HIGH
References: A-27532522*
Android Security Bulletin 2016-07-01
CVE: CVE-2016-3809
Severity: HIGH
References: A-27532522*
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-07-11
Published