Vulnerability Details CVE-2016-3828
decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28835995.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.5%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 7.1
Products affected by CVE-2016-3828
-
cpe:2.3:o:google:android:6.0
-
cpe:2.3:o:google:android:6.0.1