CVE-2016-3857

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The kernel in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 28522518.

References

http://source.android.com/security/bulletin/2016-08-01.html

Details

Source: MITRE

Published: 2016-08-05

Updated: 2016-08-10

Type: CWE-264

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:google:android:*:*:*:*:*:*:*:* versions up to 6.0.1 (inclusive)

Tenable Plugins

View all (4 total)

IDNameProductFamilySeverity
149098EulerOS 2.0 SP3 : kernel (EulerOS-SA-2021-1808)NessusHuawei Local Security Checks
high
131805EulerOS 2.0 SP5 : kernel (EulerOS-SA-2019-2531)NessusHuawei Local Security Checks
high
93601Ubuntu 12.04 LTS : linux vulnerability (USN-3082-1)NessusUbuntu Local Security Checks
high
93321Debian DLA-609-1 : linux security updateNessusDebian Local Security Checks
high