{"api_version":"1","generated_at":"2026-07-23T22:42:29+00:00","cve":"CVE-2016-6701","urls":{"html":"https://cve.report/CVE-2016-6701","api":"https://cve.report/api/cve/CVE-2016-6701.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-6701","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-6701"},"summary":{"title":"CVE-2016-6701","description":"A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637.","state":"PUBLISHED","assigner":"google_android","published_at":"2016-11-25 16:59:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-119","CWE-284","Remote code execution"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://source.android.com/security/bulletin/2016-11-01.html","name":"https://source.android.com/security/bulletin/2016-11-01.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Android Security Bulletin—November 2016 | Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94162","name":"http://www.securityfocus.com/bid/94162","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android Skia CVE-2016-6701 Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-6701","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6701","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Google Inc.","product":"Android","version":"affected Android-7.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"6701","vulnerable":"1","versionEndIncluding":"7.0","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2016","cve_id":"6701","cve":"CVE-2016-6701","epss":"0.002430000","percentile":"0.474600000","score_date":"2026-05-10","updated_at":"2026-05-11 00:14:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T01:36:29.575Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"94162","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/94162"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://source.android.com/security/bulletin/2016-11-01.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Android","vendor":"Google Inc.","versions":[{"status":"affected","version":"Android-7.0"}]}],"datePublic":"2016-11-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637."}],"problemTypes":[{"descriptions":[{"description":"Remote code execution","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-25T19:57:01.000Z","orgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","shortName":"google_android"},"references":[{"name":"94162","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/94162"},{"tags":["x_refsource_CONFIRM"],"url":"https://source.android.com/security/bulletin/2016-11-01.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@android.com","ID":"CVE-2016-6701","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Android","version":{"version_data":[{"version_value":"Android-7.0"}]}}]},"vendor_name":"Google Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Remote code execution"}]}]},"references":{"reference_data":[{"name":"94162","refsource":"BID","url":"http://www.securityfocus.com/bid/94162"},{"name":"https://source.android.com/security/bulletin/2016-11-01.html","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/2016-11-01.html"}]}}}},"cveMetadata":{"assignerOrgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","assignerShortName":"google_android","cveId":"CVE-2016-6701","datePublished":"2016-11-25T16:00:00.000Z","dateReserved":"2016-08-11T00:00:00.000Z","dateUpdated":"2024-08-06T01:36:29.575Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-11-25 16:59:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-119","CWE-284","Remote code execution"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionEndIncluding":"7.0","matchCriteriaId":"595E33EF-6B21-425B-929C-6B883FA50081"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"6701","Ordinal":"1","Title":"CVE-2016-6701","CVE":"CVE-2016-6701","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"6701","Ordinal":"1","NoteData":"A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637.","Type":"Description","Title":"CVE-2016-6701"},{"CveYear":"2016","CveId":"6701","Ordinal":"2","NoteData":"2016-11-25","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"6701","Ordinal":"3","NoteData":"2016-11-25","Type":"Other","Title":"Modified"}]}}}