CVE-2018-7993

HIGH

HUAWEI Mate 10 <ALP-AL00 8.1.0.311 - Use After Free

Title source: llm
STIX 2.1

Description

HUAWEI Mate 10 smartphones with versions earlier than ALP-AL00 8.1.0.311 have a use after free vulnerability on mediaserver component. An attacker tricks the user install a malicious application, which make the software to reference memory after it has been freed. Successful exploit could cause execution of arbitrary code.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 37.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (1)
huawei/mate_10_firmware < alp-al00_8.1.0.311
Published Jul 31, 2018
Tracked Since Feb 18, 2026