CVE-2016-6759 is an elevation of privilege vulnerability in Qualcomm media codecs affecting Android devices running Linux Kernel versions 3.10 and 3.18. A malicious local application could exploit this to execute arbitrary code within a privileged process. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires user interaction (UI:R), allowing an attacker to gain high confidentiality, integrity, and availability impacts. It enables access to elevated capabilities not typically available to third-party applications. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.10:*:*:*:*:*:*:* | ||
3.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.