CVE-2016-6702
published 2016-11-25CVE-2016-6702: A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a…
PriorityP338high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.05%
60.6th percentile
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjpeg-turbo | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-6702: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6702
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-11-01·CVSS 7.8
CVE-2016-6702 [HIGH] CVE-2016-6702: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6702
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-11-01
CVE: CVE-2016-6702
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1
References: A-30259087
Debian
CVE-2016-6702: libjpeg-turbo - A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5....
vendor_debian·2016·CVSS 7.8
CVE-2016-6702 [HIGH] CVE-2016-6702: libjpeg-turbo - A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5....
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-g9hh-j62q-7jrm: A remote code execution vulnerability in libjpeg in Android 4
ghsa_unreviewed·2022-05-17
CVE-2016-6702 [HIGH] CWE-284 GHSA-g9hh-j62q-7jrm: A remote code execution vulnerability in libjpeg in Android 4
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
OSV
CVE-2016-6702: A remote code execution vulnerability in libjpeg in Android 4
osv·2016-11-25·CVSS 7.8
CVE-2016-6702 [HIGH] CVE-2016-6702: A remote code execution vulnerability in libjpeg in Android 4
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
OSV
expat vulnerabilities
osv·2016-06-20·CVSS 5.9
CVE-2012-6702 expat vulnerabilities
expat vulnerabilities
It was discovered that Expat unexpectedly called srand in certain
circumstances. This could reduce the security of calling applications.
(CVE-2012-6702)
It was discovered that Expat incorrectly handled seeding the random number
generator. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2016-5300)
No detection rules found.
No public exploits indexed.
2016-11-25
Published