Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-15330

Опубликовано: 15 фев. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 7.1
EPSS Низкий

Описание

The Flp Driver in some Huawei smartphones of the software Vicky-AL00AC00B124D, Vicky-AL00AC00B157D, Vicky-AL00AC00B167 has a double free vulnerability. An attacker can trick a user to install a malicious application which has a high privilege to exploit this vulnerability. Successful exploitation may cause denial of service (DoS) attack.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:huawei:vicky-al00a_firmware:vicky-al00ac00b124d:*:*:*:*:*:*:*
cpe:2.3:o:huawei:vicky-al00a_firmware:vicky-al00ac00b157d:*:*:*:*:*:*:*
cpe:2.3:o:huawei:vicky-al00a_firmware:vicky-al00ac00b167:*:*:*:*:*:*:*
cpe:2.3:h:huawei:vicky-al00a:-:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00069
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-415

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

The Flp Driver in some Huawei smartphones of the software Vicky-AL00AC00B124D, Vicky-AL00AC00B157D, Vicky-AL00AC00B167 has a double free vulnerability. An attacker can trick a user to install a malicious application which has a high privilege to exploit this vulnerability. Successful exploitation may cause denial of service (DoS) attack.

EPSS

Процентиль: 21%
0.00069
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-415