High severity7.8NVD Advisory· Published Aug 5, 2016· Updated May 6, 2026
CVE-2016-3822
CVE-2016-3822
Description
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: =2.87
- osv-coords3 versionspkg:rpm/opensuse/jhead&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/jhead&distro=openSUSE%20Tumbleweedpkg:rpm/suse/jhead&distro=SUSE%20Package%20Hub%2015%20SP2
< 3.06.0.1-lp152.7.6.1+ 2 more
- (no CPE)range: < 3.06.0.1-lp152.7.6.1
- (no CPE)range: < 3.06.0.1-1.3
- (no CPE)range: < 3.06.0.1-bp152.4.6.1
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- android.googlesource.com/platform/external/jhead/+/bae671597d47b9e5955c4cb742e468cebfd7ca6bnvdIssue TrackingPatchVendor Advisory
- source.android.com/security/bulletin/2016-08-01.htmlnvdVendor Advisory
- www.debian.org/security/2017/dsa-3825nvdThird Party Advisory
- www.securityfocus.com/bid/92226nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.