Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-8159

Опубликовано: 22 нояб. 2017
Источник: nvd
CVSS3: 7.8
CVSS2: 9.3
EPSS Низкий

Описание

Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:huawei:agassi-l09hn_firmware:ags-l09c233b019:*:*:*:*:*:*:*
cpe:2.3:h:huawei:agassi-l09hn:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:huawei:agassi-w09hn_firmware:ags-w09c233b019:*:*:*:*:*:*:*
cpe:2.3:h:huawei:agassi-w09hn:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:huawei:kobe-l09ahn_firmware:kob-l09c233b017:*:*:*:*:*:*:*
cpe:2.3:h:huawei:kobe-l09ahn:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:huawei:kobe-w09chn_firmware:kob-w09c233b012:*:*:*:*:*:*:*
cpe:2.3:h:huawei:kobe-w09chn:-:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00207
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.

EPSS

Процентиль: 43%
0.00207
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-704