Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrrf-28xq-3v3x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170968514.

In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170968514.

EPSS

Процентиль: 88%
0.03739
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170968514.

EPSS

Процентиль: 88%
0.03739
Низкий

Дефекты

CWE-20