CVE-2008-0986
Google Android SDK < m3-rc37a - Numeric Error
Title source: ruleDescription
Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Alfredo Ortega · htmldosandroid
https://www.exploit-db.com/exploits/31308
References (6)
Scores
EPSS
0.1506
EPSS Percentile
94.6%
Details
CWE
CWE-189
Status
published
Products (2)
google/android_sdk
m5-rc14
google/android_sdk
< m3-rc37a
Published
Mar 06, 2008
Tracked Since
Feb 18, 2026