CVE-2017-14887

HIGH

Android - Heap Buffer Overflow in eWNI_SME_MODIFY_ADDITIONAL_IES Message Processing

Title source: llm
STIX 2.1

Description

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of messages of type eWNI_SME_MODIFY_ADDITIONAL_IES, an integer overflow leading to heap buffer overflow may potentially occur.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 8.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-190
Status published
Products (1)
google/android
Published Mar 16, 2018
Tracked Since Feb 18, 2026