CVE-2024-0016
published 2024-02-16CVE-2024-0016: In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.21%
11.6th percentile
In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 13:0 < 13:2024-01-01 | 13:2024-01-01 |
| platform | packages_modules_bluetooth | >= 14:0 < 14:2024-01-01 | 14:2024-01-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2024-0016: Android Security Bulletin 2024-01-01
CVE: CVE-2024-0016
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-279169188
[2
vendor_android·2024-01-01·CVSS 5.3
CVE-2024-0016 [MEDIUM] CVE-2024-0016: Android Security Bulletin 2024-01-01
CVE: CVE-2024-0016
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-279169188
[2
Android Security Bulletin 2024-01-01
CVE: CVE-2024-0016
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-279169188
[2]
GHSA
GHSA-8gff-fw8j-cgf3: In multiple locations, there is a possible out of bounds read due to a missing bounds check
ghsa_unreviewed·2024-02-16
CVE-2024-0016 [MEDIUM] CWE-125 GHSA-8gff-fw8j-cgf3: In multiple locations, there is a possible out of bounds read due to a missing bounds check
In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-0016: In multiple locations, there is a possible out of bounds read due to a missing bounds check
osv·2024-01-01
CVE-2024-0016 CVE-2024-0016: In multiple locations, there is a possible out of bounds read due to a missing bounds check
In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Suricata
ET DOS SMB Tree_Connect Stack Overflow Attempt (CVE-2017-0016)
suricata·2017-02-03·CVSS 5.9
CVE-2017-0016 [MEDIUM] ET DOS SMB Tree_Connect Stack Overflow Attempt (CVE-2017-0016)
ET DOS SMB Tree_Connect Stack Overflow Attempt (CVE-2017-0016)
Rule: alert tcp any 445 -> $HOME_NET any (msg:"ET DOS SMB Tree_Connect Stack Overflow Attempt (CVE-2017-0016)"; flow:established,to_client; content:"|FE|SMB"; offset:4; depth:4; content:"|03 00|"; distance:8; within:2; byte_test:1,&,1,2,relative; byte_jump:2,8,little,from_beginning; byte_jump:2,4,relative,little; isdataat:1000,relative; content:!"|FE|SMB"; within:1000; reference:cve,2017-0016; classtype:attempted-dos; sid:2023832; rev:4; metadata:affected_product SMBv3, attack_target Client_and_Server, created_at 2017_02_03, cve CVE_2017_0016, deployment Datacenter, confidence High, signature_severity Major, updated_at 2024_03_07;)
Suricata
ET EXPLOIT_KIT SunDown EK CVE-2015-0016 Sep 22 2016 (b643)
suricata·2016-09-22·CVSS 7.8
CVE-2015-0016 [HIGH] ET EXPLOIT_KIT SunDown EK CVE-2015-0016 Sep 22 2016 (b643)
ET EXPLOIT_KIT SunDown EK CVE-2015-0016 Sep 22 2016 (b643)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT SunDown EK CVE-2015-0016 Sep 22 2016 (b643)"; flow:established,to_client; flowbits:set,SunDown.EK; file.data; content:"9xb4GwTUbwUQoyD09AFIox7g9y6"; classtype:exploit-kit; sid:2023279; rev:5; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2016_09_22, cve CVE_2015_0016, malware_family SunDown, confidence High, signature_severity Major, tag Exploit_Kit_Sundown, tag CISA_KEV, updated_at 2024_03_14;)
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/packages/modules/Bluetooth/+/1d7ba7c8a205522f384e8d5c7c9f26a421cab5f1https://source.android.com/security/bulletin/2024-01-01https://android.googlesource.com/platform/packages/modules/Bluetooth/+/1d7ba7c8a205522f384e8d5c7c9f26a421cab5f1https://source.android.com/security/bulletin/2024-01-01
2024-02-16
Published