7.1

CVE-2011-1350

The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version <= 2.3.5
GoogleAndroid Version1.0
GoogleAndroid Version1.1
GoogleAndroid Version1.5
GoogleAndroid Version1.6
GoogleAndroid Version2.0
GoogleAndroid Version2.0.1
GoogleAndroid Version2.1
GoogleAndroid Version2.2
GoogleAndroid Version2.2.1
GoogleAndroid Version2.2.2
GoogleAndroid Version2.2.3
GoogleAndroid Version2.3
GoogleAndroid Version2.3.1
GoogleAndroid Version2.3.2
GoogleAndroid Version2.3.3
GoogleAndroid Version2.3.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.05% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.