nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-13323 CVE-2017-13323
HIGH
Record summary
CVE-2017-13323 has a selected CVSS score of 8.4 (high).
Description
In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 29, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AndroidBrowse Google / AndroidDefault status: unaffected, unknown | CVE List | 6 | affected |
| 6.0.1 | affected | ||
| 7 | affected | ||
| 7.1.1 | affected | ||
| 7.1.2 | affected | ||
| 8 | affected | ||
| 8.1 | affected | ||
| Before 2018-05-05 | affected | ||
Default status: unknown | CVE List | Before 2018-05-05 | affected |
References
2source.android.com
https://source.android.com/docs/security/bulletin/pixel/2018-05-01