4.3
CVSSv2

CVE-2017-0815

Published: 04/10/2017 Updated: 12/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63526567.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 7.1.2

google android 7.0

google android 6.0

google android 6.0.1

google android 5.0

google android 4.2

google android 8.0

google android 7.1.1

google android 5.0.2

google android 5.1.0

google android 4.0.3

google android 4.1

google android 4.4

google android 4.4.2

google android 4.2.1

google android 4.2.2

google android 4.3

google android 5.1.1

google android 4.0

google android 4.0.1

google android 4.0.2

google android 4.4.4

google android 7.1.0

google android 5.0.1

google android 5.1

google android 4.0.4

google android 4.1.2

google android 4.3.1

google android 4.4.1

google android 4.4.3

Recent Articles

Patch your Android, peeps, it has up to 14 nasty flaws to flog
The Register • Iain Thomson in San Francisco • 03 Oct 2017

There's a nasty bug in media file handling – deja vu, right?

Another month, another round of Android patches – although October's batch is pleasantly small compared to other recent releases. Of the 14 CVE flaws released, six cover Android's troubled media processing and playback engine. This means miscreants can fling malicious files at devices to potentially hijack them. The privilege escalation bugs can be used by dodgy apps to gain control of handsets and tablets. There's also a remote-code execution flaw in the Dnsmasq tool used by Android. Details ...