CVE-2017-18675
HIGHSamsung Android M(6.0) and N(7.x) - Information Exposure via Uninitialized Memory Leak in Camera Application
Title source: llmDescription
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 chipsets) software. The Camera application can leak uninitialized memory via ion. The Samsung ID is SVE-2016-6989 (April 2017).
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb
Scores
CVSS v3
7.5
EPSS
0.0042
EPSS Percentile
32.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-772
Status
published
Products (5)
google/android
6.0
google/android
7.0
google/android
7.1.0
google/android
7.1.1
google/android
7.1.2
Published
Apr 07, 2020
Tracked Since
Feb 18, 2026