5
CVSSv2

CVE-2016-3763

Published: 11/07/2016 Updated: 12/07/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

net/PacProxySelector.java in the Proxy Auto-Config (PAC) feature in Android 4.x prior to 4.4.4, 5.0.x prior to 5.0.2, 5.1.x prior to 5.1.1, and 6.x prior to 2016-07-01 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote malicious users to discover credentials by operating a server with a PAC script, aka internal bug 27593919.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 6.0

google android 5.1

google android 4.4.1

google android 4.3.1

google android 4.0.4

google android 4.0.2

google android 4.2.2

google android 4.2.1

google android 4.2

google android 4.1.2

google android 5.0.1

google android 5.0

google android 4.4.3

google android 4.4.2

google android 4.0

google android 6.0.1

google android 5.1.0

google android 4.4

google android 4.3

google android 4.1

google android 4.0.3

google android 4.0.1