ZeroHour

CVE-2017-18057

CVSS 3.0
7.5 high
EPSS
<1%p43
Published
()
Modified
Description

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id in wma_nlo_scan_cmp_evt_handler(), which is received from firmware, leads to potential out of bounds memory read.

Vendors
google
Products
android
Weakness
CWE-20, CWE-125
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.