← Back

CVE-2016-6704

nvd nist
Published: Nov 25, 2016Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-30229821.

Affected (5)

Products: Google: Android
1 product
Android
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Google
From 4.0 to 4.4.4
From 5.0 to 5.0.2
From 5.1 to 5.1.1
From 6.0 to 6.0.1
Version 7.0

Related CWEs

References (6)

Source: security@android.com
Third Party AdvisoryVDB Entry
Source: security@android.com
Vendor Advisory
Source: security@android.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.