CVE Vulnerabilities

CVE-2016-3746

Published: Jul 11, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Use-after-free vulnerability in the mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27890802.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle4.0 (including)4.0 (including)
AndroidGoogle4.0.1 (including)4.0.1 (including)
AndroidGoogle4.0.2 (including)4.0.2 (including)
AndroidGoogle4.0.3 (including)4.0.3 (including)
AndroidGoogle4.0.4 (including)4.0.4 (including)
AndroidGoogle4.1 (including)4.1 (including)
AndroidGoogle4.1.2 (including)4.1.2 (including)
AndroidGoogle4.2 (including)4.2 (including)
AndroidGoogle4.2.1 (including)4.2.1 (including)
AndroidGoogle4.2.2 (including)4.2.2 (including)
AndroidGoogle4.3 (including)4.3 (including)
AndroidGoogle4.3.1 (including)4.3.1 (including)
AndroidGoogle4.4 (including)4.4 (including)
AndroidGoogle4.4.1 (including)4.4.1 (including)
AndroidGoogle4.4.2 (including)4.4.2 (including)
AndroidGoogle4.4.3 (including)4.4.3 (including)
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.0.1 (including)5.0.1 (including)
AndroidGoogle5.1 (including)5.1 (including)
AndroidGoogle5.1.0 (including)5.1.0 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)
AndroidUbuntuesm-apps/xenial*
AndroidUbuntutrusty*
AndroidUbuntuvivid/stable-phone-overlay*
AndroidUbuntuwily*
AndroidUbuntuxenial*
AndroidUbuntuyakkety*
AndroidUbuntuzesty*

References