CVE-2008-0986

Google Android SDK < m3-rc37a - Numeric Error

Title source: rule

Description

Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alfredo Ortega · htmldosandroid
https://www.exploit-db.com/exploits/31308

Scores

EPSS 0.1506
EPSS Percentile 94.6%

Details

CWE
CWE-189
Status published
Products (2)
google/android_sdk m5-rc14
google/android_sdk < m3-rc37a
Published Mar 06, 2008
Tracked Since Feb 18, 2026