Sploitus

CVE-2008-0986

3 known exploits for CVE-2008-0986

Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field.

Affected products
Android Q Sdk
Google Android Sdk
≤ m3-rc37a, m5-rc14
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
4.9% (91th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2008-03-06
CVE-2008-0986 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2008-0986

Proof-of-concept code and exploit modules indexed by Sploitus