CVE-2017-11015 describes a buffer overflow vulnerability affecting Android devices utilizing Qualcomm's Mobile Station Modem (MSM) components. This flaw arises because the system allows challenge text up to 253 bytes, but the driver can only handle 128 bytes, leading to a buffer overflow. Rated 7.8 HIGH on CVSS, an attacker could exploit this locally with user interaction to achieve high confidentiality, integrity, and availability impacts. While no public exploit code or active exploitation has been observed, the vulnerability has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.