{"api_version":"1","generated_at":"2026-07-23T12:28:38+00:00","cve":"CVE-2016-9279","urls":{"html":"https://cve.report/CVE-2016-9279","api":"https://cve.report/api/cve/CVE-2016-9279.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-9279","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-9279"},"summary":{"title":"CVE-2016-9279","description":"Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-01-18 17:59:01","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-416","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2016/11/09/3","name":"http://www.openwall.com/lists/oss-security/2016/11/09/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE Request - Samsung Exynos fimg2d Multiple Issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94283","name":"http://www.securityfocus.com/bid/94283","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Samsung Mobile Phones Information Disclosure and Denial of Service Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016","name":"http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Samsung Mobile Security Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2016/11/11/11","name":"http://www.openwall.com/lists/oss-security/2016/11/11/11","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE Request - Samsung Exynos fimg2d Multiple Issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-9279","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-9279","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"9279","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"samsung","cpe5":"exynos_fimg2d_driver","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:42:11.318Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[oss-security] 20161111 Re: CVE Request - Samsung Exynos fimg2d Multiple Issues","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2016/11/11/11"},{"name":"[oss-security] 20161109 CVE Request - Samsung Exynos fimg2d Multiple Issues","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2016/11/09/3"},{"name":"94283","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/94283"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-11-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-04-24T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"[oss-security] 20161111 Re: CVE Request - Samsung Exynos fimg2d Multiple Issues","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2016/11/11/11"},{"name":"[oss-security] 20161109 CVE Request - Samsung Exynos fimg2d Multiple Issues","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2016/11/09/3"},{"name":"94283","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/94283"},{"tags":["x_refsource_CONFIRM"],"url":"http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2016-9279","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[oss-security] 20161111 Re: CVE Request - Samsung Exynos fimg2d Multiple Issues","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2016/11/11/11"},{"name":"[oss-security] 20161109 CVE Request - Samsung Exynos fimg2d Multiple Issues","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2016/11/09/3"},{"name":"94283","refsource":"BID","url":"http://www.securityfocus.com/bid/94283"},{"name":"http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016","refsource":"CONFIRM","url":"http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2016-9279","datePublished":"2017-01-18T17:00:00.000Z","dateReserved":"2016-11-11T00:00:00.000Z","dateUpdated":"2024-08-06T02:42:11.318Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-01-18 17:59:01","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-416","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:samsung:exynos_fimg2d_driver:-:*:*:*:*:*:*:*","matchCriteriaId":"1FE6484A-1FF8-413F-A39F-AB0E8216EA5F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"9279","Ordinal":"1","Title":"CVE-2016-9279","CVE":"CVE-2016-9279","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"9279","Ordinal":"1","NoteData":"Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.","Type":"Description","Title":"CVE-2016-9279"},{"CveYear":"2016","CveId":"9279","Ordinal":"2","NoteData":"2017-01-18","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"9279","Ordinal":"3","NoteData":"2017-04-24","Type":"Other","Title":"Modified"}]}}}