CVE-2016-6761
published 2017-01-12CVE-2016-6761: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a…
PriorityP338high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.61%
73.2th percentile
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29421682. References: QC-CR#1055792.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r9qv-22jm-xqjj: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the conte
ghsa_unreviewed·2022-05-17
CVE-2016-6761 [HIGH] CWE-284 GHSA-r9qv-22jm-xqjj: An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the conte
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-29421682. References: QC-CR#1055792.
Android
CVE-2016-6761: Android Security Bulletin 2016-12-01
CVE: CVE-2016-6761
Severity: HIGH
References: A-29421682*
QC-CR#1055792
vendor_android·2016-12-01·CVSS 7.8
CVE-2016-6761 [HIGH] CVE-2016-6761: Android Security Bulletin 2016-12-01
CVE: CVE-2016-6761
Severity: HIGH
References: A-29421682*
QC-CR#1055792
Android Security Bulletin 2016-12-01
CVE: CVE-2016-6761
Severity: HIGH
References: A-29421682*
QC-CR#1055792
Red Hat
kernel: v4l: videobuf: hotfix a bug on multiple calls to mmap()
vendor_redhat·2010-07-29·CVSS 7.8
CVE-2010-5321 [HIGH] kernel: v4l: videobuf: hotfix a bug on multiple calls to mmap()
kernel: v4l: videobuf: hotfix a bug on multiple calls to mmap()
Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new allocations, a different vulnerability than CVE-2007-6761. NOTE: as of 2016-06-18, this affects only 11 drivers that have not been updated to use videobuf2 instead of videobuf.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2.
Based on the absence of upstream patch addressing this issue in
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-01-12
Published