CVE-2016-2417
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 5.3%
from disclosure to weapon0 days
Published on NVDApr 18
1st PoCApr 11
exploitation probability
5.3%top 8% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39685cve_referencewww.exploit-db.com/exploits/39685/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.