CVE-2016-0808
Last modified
CVE-2016-0808 is a vulnerability of currently unknown severity. Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 5.0 | |
| Android | 5.0.1 | |
| Android | 5.0.2 | |
| Android | 5.1 | |
| Android | 5.1.0 | |
| Android | 5.1.1 | |
| Android | 6.0 | |
| Android | 6.0.1 |
References
- http://source.android.com/security/bulletin/2016-02-01.htmlVendor Advisory
- http://source.android.com/security/bulletin/2016-02-01.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-0808?
How severe is CVE-2016-0808?
How do I fix CVE-2016-0808?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-0802The Broadcom Wi-Fi driver in the kernel in Android 4.x befor…
- CVE-2016-0803libstagefright in mediaserver in Android 4.x before 4.4.4, 5…
- CVE-2016-0804The NuPlayer::GenericSource::notifyPreparedAndCleanup functi…
- CVE-2016-0805The performance event manager for Qualcomm ARM processors in…
- CVE-2016-0806The Qualcomm Wi-Fi driver in the kernel in Android 4.x befor…
- CVE-2016-0807The get_build_id function in elf_utils.cpp in Debuggerd in A…
- CVE-2016-0809Use-after-free vulnerability in the wifi_cleanup function in…
- CVE-2016-0810media/libmedia/SoundPool.cpp in mediaserver in Android 4.x b…
- CVE-2016-0811Integer overflow in the BnCrypto::onTransact function in med…
- CVE-2016-0812The interceptKeyBeforeDispatching function in policy/src/com…
- CVE-2016-0813packages/SystemUI/src/com/android/systemui/recents/Alternate…
- CVE-2016-0815The MPEG4Source::fragmentedRead function in MPEG4Extractor.c…
Are you affected by CVE-2016-0808?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
