CVE-2017-0634 is an information disclosure vulnerability affecting the Synaptics touchscreen driver in Android devices running Kernel-3.18. A local malicious application could exploit this to access data beyond its authorized permissions. Rated Medium with a CVSS score of 4.7, exploitation requires user interaction and a high attack complexity, as it first necessitates compromising a privileged process. The primary impact is a high risk of confidentiality compromise. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei. The vulnerability has received minimal community attention and media coverage, suggesting a low profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.