CVE-2017-11013 is a buffer overflow vulnerability (CWE-120) affecting Google Android devices utilizing the Linux kernel, specifically within the UnpackCore function where a lack of boundary checks allows countOffset to exceed arraybound. This vulnerability carries a high CVSSv3 score of 7.8, indicating a significant risk with local access and user interaction required for exploitation, potentially leading to high impact on confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or widespread community discussion, though it did receive limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.