7.5

CVE-2017-18675

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 chipsets) software. The Camera application can leak uninitialized memory via ion. The Samsung ID is SVE-2016-6989 (April 2017).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 6.0
   Samsung ≫ Exynos 7420 Version -
   Samsung ≫ Exynox 8890 Version -
Google ≫ Android Version 7.0
   Samsung ≫ Exynos 7420 Version -
   Samsung ≫ Exynox 8890 Version -
Google ≫ Android Version 7.1.0
   Samsung ≫ Exynos 7420 Version -
   Samsung ≫ Exynox 8890 Version -
Google ≫ Android Version 7.1.1
   Samsung ≫ Exynos 7420 Version -
   Samsung ≫ Exynox 8890 Version -
Google ≫ Android Version 7.1.2
   Samsung ≫ Exynos 7420 Version -
   Samsung ≫ Exynox 8890 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.33
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

https://security.samsungmobile.com/securityUpdate.smsb
Vendor Advisory