CVE-2016-0834 describes a critical memory corruption vulnerability within an unspecified media codec in Android's mediaserver component, affecting Android 6.x versions prior to the April 2016 security update. This flaw allows remote attackers to execute arbitrary code or trigger a denial of service by processing a specially crafted media file. With a CVSS score of 8.4 (High), it poses a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is currently reported, the vulnerability has garnered some community discussion and media coverage, indicating its recognized severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.