CVE-2016-2454
MEDIUMGoogle Android < 6.0.1 - Improper Input Validation
Title source: ruleDescription
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
Scores
CVSS v3
5.5
EPSS
0.0028
EPSS Percentile
51.2%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-20
Status
draft
Affected Products (1)
google/android
< 6.0.1
Timeline
Published
May 09, 2016
Tracked Since
Feb 18, 2026