CVE-2016-5863
published 2017-08-16CVE-2016-5863: In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to…
PriorityP432high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.55%
42.7th percentile
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| linux | linux_kernel | >= 0 < 3.13.0-95.142 | 3.13.0-95.142 |
| linux | linux_kernel | >= 0 < 4.4.0-36.55 | 4.4.0-36.55 |
| qualcomm_inc | all_qualcomm_products | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c3jv-xx3c-w254: In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lea
ghsa_unreviewed·2022-05-17
CVE-2016-5863 [HIGH] GHSA-c3jv-xx3c-w254: In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lea
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
OSV
CVE-2016-5863: In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lea
osv·2017-08-16·CVSS 7.8
CVE-2016-5863 [HIGH] CVE-2016-5863: In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lea
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
Android
CVE-2016-5863: USB HID driver
vendor_android·2017-07-01·CVSS 7.8
CVE-2016-5863 [HIGH] CVE-2016-5863: USB HID driver
Android Security Bulletin 2017-07-01
CVE: CVE-2016-5863
Severity: MEDIUM
Type: EoP
Component: USB HID driver
References: A-36251182
QC-CR#1102936
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99465https://source.android.com/security/bulletin/2017-07-01https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=daf0acd54a6a80de227baef9a06285e4aa5f8c93http://www.securityfocus.com/bid/99465https://source.android.com/security/bulletin/2017-07-01https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=daf0acd54a6a80de227baef9a06285e4aa5f8c93
2017-08-16
Published