CVE-2016-6709

All FrameworksAndroidCWE-OtherCVE-2016-6709

CVE-2016-6709

State: PUBLISHED · Published: 2016-11-25 · Updated: 2024-08-06 · Assigner: google_android
Description
An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission. Android ID: A-31081987.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2016/6xxx/CVE-2016-6709.json