5.1

CVE-2024-39427

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleAndroid Version12.0
   UnisocS8000 Version-
   UnisocSc7731e Version-
   UnisocSc9832e Version-
   UnisocSc9863a Version-
   UnisocT310 Version-
   UnisocT606 Version-
   UnisocT610 Version-
   UnisocT612 Version-
   UnisocT616 Version-
   UnisocT618 Version-
   UnisocT760 Version-
   UnisocT770 Version-
   UnisocT820 Version-
GoogleAndroid Version13.0
   UnisocS8000 Version-
   UnisocSc7731e Version-
   UnisocSc9832e Version-
   UnisocSc9863a Version-
   UnisocT310 Version-
   UnisocT606 Version-
   UnisocT610 Version-
   UnisocT612 Version-
   UnisocT616 Version-
   UnisocT618 Version-
   UnisocT760 Version-
   UnisocT770 Version-
   UnisocT820 Version-
GoogleAndroid Version14.0
   UnisocS8000 Version-
   UnisocSc7731e Version-
   UnisocSc9832e Version-
   UnisocSc9863a Version-
   UnisocT310 Version-
   UnisocT606 Version-
   UnisocT610 Version-
   UnisocT612 Version-
   UnisocT616 Version-
   UnisocT618 Version-
   UnisocT760 Version-
   UnisocT770 Version-
   UnisocT820 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.027
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
security@unisoc.com 5.1 2.5 2.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.