CVE-2016-5863 Information
Feb 14, 2021
cve
Description
In an ioctl handler in all Qualcomm products with Android for MSM Firefox OS for MSM or QRD Android several sanity checks are missing which can lead to out-of-bounds accesses.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/99465 https://source.android.com/security/bulletin/2017-07-01 https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=daf0acd54a6a80de227baef9a06285e4aa5f8c93
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: