CVE-2016-6702
HIGHGoogle Android - Improper Access Control
Title source: ruleDescription
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
Exploits (1)
github
WRITEUP
8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/android/CVE-2016-6702
Scores
CVSS v3
7.8
EPSS
0.0042
EPSS Percentile
61.8%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-284
Status
draft
Affected Products (20)
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
google/android
... and 5 more
Timeline
Published
Nov 25, 2016
Tracked Since
Feb 18, 2026