← back
CVE-2016-5864

CVE-2016-5864

EPSS 0.6%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Aug 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow. In another function, a missing check for a lower bound may result in an out of bounds memory access.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →