SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-11087

libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of…

HIGH 7.5EPSS 0.51%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of mediaserver.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.51% probability · 42th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
google/android
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.