CVE-2018-6254

LOW

Google Android < 8.1 - Information Disclosure

Title source: rule
STIX 2.1

Description

In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-64340684. Reference: N-CVE-2018-6254.

References (1)

Core 1
Core References

Scores

CVSS v3 3.3
EPSS 0.0004
EPSS Percentile 11.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-125 CWE-200
Status published
Products (1)
google/android < 8.1
Published May 10, 2018
Tracked Since Feb 18, 2026