ZeroHour

CVE-2016-1155

CVSS 3.0
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.

Vendors
google
Products
android
Weakness
CWE-74
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.