6.2

CVE-2016-0808

Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 5.0
Google ≫ Android Version 5.0.1
Google ≫ Android Version 5.0.2
Google ≫ Android Version 5.1
Google ≫ Android Version 5.1.0
Google ≫ Android Version 5.1.1
Google ≫ Android Version 6.0
Google ≫ Android Version 6.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.077
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.2 2.5 3.6
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://source.android.com/security/bulletin/2016-02-01.html
Vendor Advisory
https://android.googlesource.com/platform/frameworks/minikin/+/ed4c8d79153baab7f26562afb8930652dfbf853b