Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96m3-53rw-386g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

EPSS

Процентиль: 84%
0.02415
Низкий

7.5 High

CVSS3

Дефекты

CWE-125
CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

CVSS3: 7.5
redhat
больше 5 лет назад

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

CVSS3: 7.5
nvd
больше 5 лет назад

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

CVSS3: 7.5
debian
больше 5 лет назад

In vp8_decode_frame of decodeframe.c, there is a possible out of bound ...

suse-cvrf
около 5 лет назад

Security update for libvpx

EPSS

Процентиль: 84%
0.02415
Низкий

7.5 High

CVSS3

Дефекты

CWE-125
CWE-20