CVE-2017-18127
—CVSS 3.0
9.8 critical
EPSS
1%p69
Published
()
Modified
Description
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 835, SD 845, while processing a SetParam command packet in the VR service, the extracted name_len and value_len values are not checked and could potentially cause a buffer overflow in subsequent calls to memcpy().
- Vendors
- qualcomm
- Products
- msm8909w firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 430 firmware, sd 450 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware, sd 820 firmware, sd 835 firmware, sd 845 firmware
- Weakness
- CWE-119
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.