CVE-2016-3855
published 2016-08-06CVE-2016-3855: drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to…
PriorityP429high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.39%
31.3th percentile
drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR990824.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 6.0.1 | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ggcw-2659-h4vh: drivers/thermal/supply_lm_core
ghsa_unreviewed·2022-05-17
CVE-2016-3855 [HIGH] CWE-125 GHSA-ggcw-2659-h4vh: drivers/thermal/supply_lm_core
drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR990824.
OSV
CVE-2016-3855: drivers/thermal/supply_lm_core
osv·2016-08-06·CVSS 7.8
CVE-2016-3855 [HIGH] CVE-2016-3855: drivers/thermal/supply_lm_core
drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR990824.
Android
CVE-2016-3855: Android Security Bulletin 2016-08-01
CVE: CVE-2016-3855
Severity: HIGH
References: QC-CR#990824
vendor_android·2016-08-01·CVSS 7.8
CVE-2016-3855 [HIGH] CVE-2016-3855: Android Security Bulletin 2016-08-01
CVE: CVE-2016-3855
Severity: HIGH
References: QC-CR#990824
Android Security Bulletin 2016-08-01
CVE: CVE-2016-3855
Severity: HIGH
References: QC-CR#990824
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.securityfocus.com/bid/92256https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=ab3f46119ca10de87a11fe966b0723c48f27acd4http://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.securityfocus.com/bid/92256https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=ab3f46119ca10de87a11fe966b0723c48f27acd4
2016-08-06
Published