CVE-2016-6604 describes a critical NULL pointer dereference vulnerability in the Samsung Exynos fimg2d driver, affecting Android L (5.0/5.1) and M (6.0) on Samsung devices. This flaw allows attackers to achieve a severe impact, including potential compromise of confidentiality, integrity, and availability, via unspecified network-based vectors. With a CVSSv3 score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without user interaction. The potential impact is high across all security metrics, indicating a significant risk. While there is no known active exploitation (KEV list) or publicly available exploit code (Metasploit, ExploitDB, Nuclei), the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness and interest within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:samsung:exynos_fimg2d:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.