CVE Vulnerabilities

CVE-2016-3832

Published: Aug 05, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
8.3 HIGH
AV:N/AC:M/Au:N/C:P/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 do not ensure that package data originated from the Package Manager, which allows attackers to bypass an unspecified protection mechanism via a crafted application, aka internal bug 28795098.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle4.0 (including)4.0 (including)
AndroidGoogle4.0.1 (including)4.0.1 (including)
AndroidGoogle4.0.2 (including)4.0.2 (including)
AndroidGoogle4.0.3 (including)4.0.3 (including)
AndroidGoogle4.0.4 (including)4.0.4 (including)
AndroidGoogle4.1 (including)4.1 (including)
AndroidGoogle4.1.2 (including)4.1.2 (including)
AndroidGoogle4.2 (including)4.2 (including)
AndroidGoogle4.2.1 (including)4.2.1 (including)
AndroidGoogle4.2.2 (including)4.2.2 (including)
AndroidGoogle4.3 (including)4.3 (including)
AndroidGoogle4.3.1 (including)4.3.1 (including)
AndroidGoogle4.4 (including)4.4 (including)
AndroidGoogle4.4.1 (including)4.4.1 (including)
AndroidGoogle4.4.2 (including)4.4.2 (including)
AndroidGoogle4.4.3 (including)4.4.3 (including)
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.0.1 (including)5.0.1 (including)
AndroidGoogle5.1 (including)5.1 (including)
AndroidGoogle5.1.0 (including)5.1.0 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)
AndroidUbuntuesm-apps/xenial*
AndroidUbuntutrusty*
AndroidUbuntuvivid/stable-phone-overlay*
AndroidUbuntuxenial*
AndroidUbuntuyakkety*
AndroidUbuntuzesty*

References