Описание
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*
EPSS
Процентиль: 0%
0.00069
Низкий
3.3 Low
CVSS3
Дефекты
CWE-120
Связанные уязвимости
CVSS3: 3.3
github
2 месяца назад
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS3: 3.3
fstec
2 месяца назад
Уязвимость метода setTo сценария ResourceTypes.cpp компонента Framework операционных систем Android, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
Процентиль: 0%
0.00069
Низкий
3.3 Low
CVSS3
Дефекты
CWE-120